HDS ViewStation System Administrator's Guide

A Hypertext Document


ViewStation Password Encryption

This page describes the ViewStation's use of encrypted passwords and the "hdscrypt" program used for the encryption.

Password Security
The ViewStation's password is not displayed on any screen. It must be entered before it is changed, either locally or remotely. The password can be encrypted if it needs to be transmitted over the network; the ViewStation will read and decrypt the password before it does its password verification.

If the system administrator sets a password in the configuration file and then sets that file to be saved in NVM, the user cannot change the password unless he knows it and has access to Setup Mode and the configuration file. The configuration password and the NVM (Setup Mode) password must always match. If the configuration password is loaded first, it is used as the current Setup Mode password; if the NVM password is loaded first, the configuration file (with all its settings) is discarded if its password doesn't match the NVM password. Since many Setup Mode fields, such as fontpaths, IP addresses, privileged Console window commands, etc. are protected by this Setup Mode password, important ViewStation settings are secure.

Handling the password on the network system needs some care.

Passwords in Bootp
If you use Bootp with your first time startup to load the configuration file, you must use TFTP as the file transfer protocol (or anonymous FTP with its username and password to load the file), and since TFTP requires a world-readable file, the password in the configuration file must be encrypted to preserve its integrity. The password in the bootp table itself can appear in clear text since this file belongs to the root user and can be hidden or read-protected. In this way, the level of system security of the root user is extended to each ViewStation.

If you use the ViewStation to load the configuration file directly , you can use the FTP or NFS protocols for the file transfer. You can also read-protect the file, so you can use the password in clear text.

Using hdscrypt Encryption
This page describes the hdscrypt encryption program.

Return to Section Heading Page


Return to the Home Page

If you need more information than is available here, you can reach HDS via email at info@hds.com, or call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside the US. For questions or problems regarding the HDS WWW page, contact webmaster@hds.com.
© 1996 by HDS Network Systems Inc.