Skip to content

Add Cisco IOS type 6, 7, 8 and 9 secret formats - #5

Merged
antoinekh merged 42 commits into
masterfrom
cisco-secret-formats
Aug 19, 2026
Merged

antoinekh merged 42 commits into
masterfrom
cisco-secret-formats

Conversation

@antoinekh

Copy link
Copy Markdown
Owner

Adds the four Cisco IOS secret formats to the Python package, the CLI and the website.

Closes #2, closes #3, closes #4.

Formats

Type Construction Reversible
6 MD5-derived AES-128 key, counter-mode keystream, HMAC-SHA1 tag, base41 armour yes, keyed by the device master key
7 XOR against a fixed key string yes, keyless
8 PBKDF2-HMAC-SHA256, 20000 iterations no, one-way hash
9 scrypt, N=16384 r=1 p=1 no, one-way hash

All four are verified against Cisco's own published test vectors from CiscoDevNet/Type-6-Password-Encode, in both the Python and the TypeScript implementation. No new Python dependency; scrypt-js is the single new web dependency, because Web Crypto has no scrypt.

One thing worth knowing about type 6

IOS encrypts and authenticates the secret's trailing NUL byte: ios_encrypt_password.c loops i <= pass_len. The encode6.py script Cisco publishes in the same repository omits that byte, so it round-trips against itself but does not reproduce what a device emits. This implementation follows the C reference and is byte-exact against Cisco's published vector. tests/test_cisco_type6.py::test_encrypt_reproduces_the_cisco_vector_exactly is the regression guard.

One-way formats keep the existing contract

Type 8 and type 9 use the same Cipher shape as the reversible formats: encrypt hashes, check verifies a candidate password by reusing the salt from the given hash, and decrypt raises. --list and the subcommand help both carry the (one-way) marker. On the site they get Hash and Verify tabs instead of Encode and Decode, and a One-way badge in the catalogue.

Prefix collision

Cisco $8$ and $9$ are the same markers Juniper/HPE uses for unrelated algorithms. Nothing auto-detects between them; the format is always chosen explicitly by subcommand or by page. The README and the affected format pages say so.

Also in here

  • Fixes a latent CLI bug: key environment variables were resolved by key kind rather than per cipher, so Cisco type 6 would have read JUNOS_MASTER_PASSWORD. Each registry entry now declares its own variable.
  • Groups the site navigation by vendor, since a flat tab row no longer holds ten entries. Each vendor opens a menu on hover, click or tap, and Escape returns focus to the trigger.
  • Adds a header link to the source repository.
  • Points the $9$ and $8$ source links at network-secret instead of the superseded juniper9-crypt and juniper8-crypt.
  • Refreshes uv.lock, which recorded 0.1.0 while pyproject.toml said 0.1.1.

Verification

Python 139 tests, web 140 tests, npm run check clean, npm run build succeeds. Every known-answer vector passes through the CLI. The site was checked by hand in a browser across several rounds.

Known gap: no automated test covers the navigation menu's pointer behaviour. A DOM-level test needs a Svelte component-test harness, which is more dependencies than this branch should introduce, so it belongs in its own change.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Deploying network-secret with  Cloudflare Pages  Cloudflare Pages

Latest commit: 059c431
Status: ✅  Deploy successful!
Preview URL: https://f51ae712.network-secret.pages.dev
Branch Preview URL: https://cisco-secret-formats.network-secret.pages.dev

View logs

@antoinekh
antoinekh merged commit 8734115 into master Aug 19, 2026
5 checks passed
@antoinekh
antoinekh deleted the cisco-secret-formats branch August 19, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support for Cisco type8/9 Support for Cisco type7 Support for Cisco type6

1 participant