HPE Aruba Networking & ProVision-based
1833752 Members
2567 Online
110063 Solutions
New Discussion

HP Procurve 15.x config gathered via SCP get is missig the radius keys

 
mherculea
Respected Contributor

HP Procurve 15.x config gathered via SCP get is missig the radius keys

Hi,

 

I have a problem which hopefully someone has encountered before.

 

Whenever I try to retrieve the configuration of a HP ProCurve switch 2920-48G-POE+/j9729a version WB.15.15.0008 (tested on WB.15.14 aswell) via SCP GET method the radius keys are missing.

 

I get:

...

radius-server host 10.zz.2.yy 
radius-server host 10.zz.2.yy
radius-server host 10.zz.3.yy  

...

instead of 

...

radius-server host 10.zz.2.yx key xxx
radius-server host 10.zz.2.yz key xxz
radius-server host 10.zz.3.yy  key xxy

...

 

I confirm via SSH show config commands that the radius key shared passwords exist.

 

Anyone seen this before? Any pointers as to the cause?

 

Kind regards,

Marius Herculea
HP SW Technical Consultant

Cloud and Automation Professional Services

1 REPLY 1
mherculea
Respected Contributor

Re: HP Procurve 15.x config gathered via SCP get is missig the radius keys

Ok,

 

So looking further, I seems it`s by design

 

Note on RADIUS and TACACS keys:

When copying off a switch configuration, certain security parameters, including the RADIUS and TACACS keys, are not included in the copied configuration. If this configuration is then used to restore a device configuration, it will not

include this information, possibly resulting in a user being denied access due to a mismatched password that is no longer encrypted.

 

That said, is there a way to enable the inclusion of the security parameters when copying it?
 
Best regards,
 
Marius Herculea
HP SW Technical Consultant

Cloud and Automation Professional Services