This page describes the ViewStation's use of encrypted
passwords and the "hdscrypt" program used for the encryption.
Password Security
The ViewStation's password is not displayed on any screen. It must
be entered before it is changed, either locally or remotely. The
password can be encrypted if it needs to be transmitted over the
network; the ViewStation will read and decrypt the password before it
does its password verification.
If the system administrator
sets a password in the configuration file and then sets that file to be
saved in NVM, the user cannot change the password unless he knows it
and has access to Setup Mode and the configuration file. The
configuration password and the NVM (Setup Mode) password must always
match. If the configuration password is loaded first, it is used as
the current Setup Mode password; if the NVM password is loaded first,
the configuration file (with all its settings) is discarded if its
password doesn't match the NVM password. Since many Setup Mode fields,
such as fontpaths, IP addresses, privileged Console window commands,
etc. are protected by this Setup Mode password, important ViewStation
settings are secure.
Handling the password on the network system needs some care.
Passwords in Bootp
If you use Bootp with your first time startup to load the
configuration file, you must use TFTP as the file transfer protocol (or
anonymous FTP with its username and password to load the file), and
since TFTP requires a world-readable file, the password in the
configuration file must be encrypted to preserve its integrity. The
password in the bootp table itself can appear in clear text since this
file belongs to the root user and can be hidden or read-protected. In
this way, the level of system security of the root user is extended to
each ViewStation.
If you use the ViewStation to load the configuration file
directly , you can use the FTP or NFS protocols for the file transfer.
You can also read-protect the file, so you can use the password in
clear text.
Using hdscrypt Encryption
This page describes the hdscrypt encryption program.
Return to Section Heading Page
Return to the Home Page
If you need more information than is available here, you can reach
HDS via email at info@hds.com, or
call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside
the US. For questions or problems regarding the HDS WWW page, contact
webmaster@hds.com.
© 1996 by HDS Network Systems
Inc.