HDS ViewStation System Administrator's Guide

A Hypertext Document


Using the ViewStation's hdscrypt Encryption Program

This page describes the ViewStation's hdscrypt encryption program.

Password Encryption with hdscrypt The ViewStation has an decryption routine built into its server (based on a public-domain routine called "crypt" which is included with MicroEMACS written and copyrighted by Dana L. Hoggett; this program, renamed "hdscrypt" to avoid confusion with other encryption programs, can be obtained directly from HDS). This encryption program allows you to encrypt your password and then have the ViewStation decrypt it for comparison with the Setup Mode password(s) as needed.

To use Bootp to load a configuration file at initial startup, you must use TFTP (or anonymous FTP with a username and password). The configuration file itself must have read permission for TFTP (and the rest of the world) in order to be moved. If the Setup Mode password is used in the configuration file, it must be encrypted to preserve its integrity.

Using hdscrypt
Using the hdscrypt program is simple. When you run the hdscrypt program, it requests a "key", that is, your user password, which serves as the basis for the encryption scheme. In this example:

hdssun12: hdscrypt
Enter Key rembrandt
rembrandt
Encrypts to: [IXWnI`&}z]


the Key entered is "rembrandt", which is the user's password. You then re-enter the password and it is encrypted against this Key. The encrypted password is then displayed in brackets. You can encrypt other passwords (such as the FTP password) using this same key, but note that all the passwords in the configuration file must use that encryption key, since the decryption is done against the same key.

This password (key) is also entered in the T128 field in the bootptab file as plain text. The encrypted password "IXWnl'&}z" is the entry you make in the configuration file. When the configuration file is loaded into the ViewStation, the ViewStation server code (which also runs the hdscrypt program) examines the entry and decrypts it into "rembrandt", which it then compares to the password entered by the user in its Setup Mode or its NVM. The NVM password and the bootptab passwords must be the same, and only the encrypted password appears in the configuration file. Since the bootp protocol and bootptab are controlled exclusively by the superuser, they may be protected or hidden.

Note that special characters, like spaces, can be used in encrypted passwords if they are enclosed in double quotes "". This ViewStation feature is present in boot prom versions 3.0 and higher.

With HDSware 3.0.3 (you must use both bootprom code and server code at the V3.0.3 level), the ViewStation accepts any password in the configuration file as plain text or encrypted text.

Return to Section Heading Page


Return to the Home Page

If you need more information than is available here, you can reach HDS via email at info@hds.com, or call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside the US. For questions or problems regarding the HDS WWW page, contact webmaster@hds.com.
© 1996 by HDS Network Systems Inc.