[nsp] cisco password hash problems?

Jared Mauch jared at puck.nether.net
Tue Apr 13 15:21:40 EDT 2004


On Tue, Apr 13, 2004 at 08:50:19PM +0300, Hank Nussbacher wrote:
> On Tue, 13 Apr 2004, Bruce Pinsky wrote:
> 
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > Hank Nussbacher wrote:
> >
> > | At 11:17 PM 12-04-04 -0400, jlewis at lewis.org wrote:
> > |
> > | I tried opening a TAC case (E818245) back on Dec 4 on this but Cisco
> > | told me to look at CSCdw75860 which only addressed the problem in OSPF
> > | but we could not convince them we saw it in BGP password hash as well.
> > |
> >
> >
> > Were you able to consistently recreate it?  What version?  How?
> 
> Recreate it?  I should downgrade my routers so as to provide debugging?
> :-)
> 
> Versions: 12.0(25)S2 upgraded to 12.2(18)S1 and "some" OSPF+BGP Md5 pswds
> stopped working.  Not all - just some.

	I experienced this with some vty passwords.

	Seems cisco doesn't have this tested in their lab at all.

	- jared

> > I found several BGP/MD5 issues including:
> >
> > 	CSCeb07106 BGP and md5 authentication issues - TCP-6-TOOBIG
> > ~ 	CSCeb06813 BGP Peer will not come up after disabling MD5
> > 	CSCec29952 bgp md5 authentication not working when configured in 			mpls
> > vpn vrf
> > 	CSCed65333 Malformed sync ack packet with BGP MD5 authentication

CSCdw39691 BGP neighbor established when password config on one side only

	- Jared

-- 
Jared Mauch  | pgp key available via finger from jared at puck.nether.net
clue++;      | http://puck.nether.net/~jared/  My statements are only mine.


More information about the cisco-nsp mailing list