Configuring Username and Password Security

Saving Security Credentials in a Config File

By storing different security settings in different files, you can test different security configurations when you first download a new software version that supports multiple configuration files, by changing the configuration file used when you reboot the switch.

For more information about how to experiment with, upload, download, and use configuration files with different software versions, refer to the following:

The chapter on “Switch Memory and Configuration” in the Management and Configuration Guide.

“Configuring Local Password Security” on page 2-6in this guide.

Enabling the Storage and Display of Security Credentials

To enable the security settings, enter the include-credentialscommand.

Syntax: [no] include-credentials

Enables the inclusion and display of the currently configured manager and operator usernames and passwords, RADIUS shared secret keys, SNMP and 802.1X authenticator (port-access) security credentials, and SSH client public-keys in the running configuration. (Earlier software releases store these security configuration settings only in internal flash memory and do not allow you to include and view them in the running-config file.) To view the currently configured security settings in the running configuration, enter one of the following commands:

show running-config:Displays the configuration settings in the current running-config file.

write terminal: Displays the configuration settings in the current running-config file.

For more information, refer to “Switch Memory and Configuration” in the Management and Configuration Guide. The “no” form of the command disables only the display and copying of these security parameters from the running configuration, while the security settings remain active in the running configuration. Default: The security credentials described in “Security Settings that Can Be Saved” on page 2-11are not stored in the running configuration.

Security Settings that Can Be Saved

The security settings that can be saved to a configuration file are:

Local manager and operator passwords and user names

2-11