Repository navigation
Add Cisco IOS type 6, 7, 8 and 9 secret formats - #5
Merged
Merged
Conversation
Deploying network-secret with
|
| Latest commit: |
059c431
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://f51ae712.network-secret.pages.dev |
| Branch Preview URL: | https://cisco-secret-formats.network-secret.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the four Cisco IOS secret formats to the Python package, the CLI and the website.
Closes #2, closes #3, closes #4.
Formats
All four are verified against Cisco's own published test vectors from CiscoDevNet/Type-6-Password-Encode, in both the Python and the TypeScript implementation. No new Python dependency;
scrypt-jsis the single new web dependency, because Web Crypto has no scrypt.One thing worth knowing about type 6
IOS encrypts and authenticates the secret's trailing NUL byte:
ios_encrypt_password.cloopsi <= pass_len. Theencode6.pyscript Cisco publishes in the same repository omits that byte, so it round-trips against itself but does not reproduce what a device emits. This implementation follows the C reference and is byte-exact against Cisco's published vector.tests/test_cisco_type6.py::test_encrypt_reproduces_the_cisco_vector_exactlyis the regression guard.One-way formats keep the existing contract
Type 8 and type 9 use the same
Ciphershape as the reversible formats:encrypthashes,checkverifies a candidate password by reusing the salt from the given hash, anddecryptraises.--listand the subcommand help both carry the(one-way)marker. On the site they get Hash and Verify tabs instead of Encode and Decode, and aOne-waybadge in the catalogue.Prefix collision
Cisco
$8$and$9$are the same markers Juniper/HPE uses for unrelated algorithms. Nothing auto-detects between them; the format is always chosen explicitly by subcommand or by page. The README and the affected format pages say so.Also in here
JUNOS_MASTER_PASSWORD. Each registry entry now declares its own variable.$9$and$8$source links atnetwork-secretinstead of the supersededjuniper9-cryptandjuniper8-crypt.uv.lock, which recorded 0.1.0 whilepyproject.tomlsaid 0.1.1.Verification
Python 139 tests, web 140 tests,
npm run checkclean,npm run buildsucceeds. Every known-answer vector passes through the CLI. The site was checked by hand in a browser across several rounds.Known gap: no automated test covers the navigation menu's pointer behaviour. A DOM-level test needs a Svelte component-test harness, which is more dependencies than this branch should introduce, so it belongs in its own change.