aaa authentication attempts class-override unknown hash-username

Prev Next

Protects unknown user names by hashing them.

An unknown user name is one that is not recognized as a locally configured account.

This command applies a hash function to the unknown user name, and stores the hashed result in place of the original. This is offered for security purposes, since sometimes unknown user names can include sensitive information. For example, sometimes users enter their passwords accidentally when prompted for a user name, and the password would otherwise end up stored and printed in plain text.

Note

This command only applies to the admin user account. It does not apply to other user accounts with administrative privileges.

Syntax

[no] aaa authentication attempts class-override unknown hash-username

Parameters

no

Use the no form of this command to remove the hash-username override from unknown users and store unknown user names as plain text.

Example

The following command hashes unknown user names:

hostname (config) # aaa authentication attempts class-override unknown hash-username

The following command stores unknown user names as plaintext:

hostname (config) # no aaa authentication attempts class-override unknown hash-username

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis:: Before release 6.4

  • Central Management System: 7.1

  • Email Security — Server: Before release 6.4

  • File Protect: Before release 6.4

  • Endpoint Security (HX): 2.5

  • Network Security: Before release 6.4

  • Intelligent Virtual Execution - Server: 7.9