[c-nsp] Hiding SCP Password Using Archive Feature

Richard Clayton via cisco-nsp <[email protected]> Sat, 29 Apr 2023 14:47:59 +0100
Newsgroups gmane.network.nsp.cisco
Message-ID <CAEjRv+-=PhNwe_xWzwweqgJh-8L13H2N3FrAd=r7ZUfLwX+uKw@mail.gmail.com>
Hi Guys

What I'm trying to achieve:

1.  Every time an engineer runs the write-memory command, a copy of the
running config is sent to my SCP server.
2.  Every 7 days, a copy of the running config is sent to my SCP server.
3. The password in configuration is not shown in clear text.

It's just #3 that I hope there is a fix for.

Here is an example of my config.

archive
 path scp://
user:[email protected]/CUSTOMERS/CUSTOMER1/CUSTOMER-LONDON6-ETH1.cfg
 write-memory
 time-period 10080

Because the password part of the SCP config is not an IOS recognised
password I don't appear to be able to encrypt it.  If that's the case is
there a secure fudge, like somehow referencing a local username that does
have password encryption.

I'm not looking for server based solutions like SolarWinds etc.

Thanks
Rick
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.