<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cfg export + master key hash in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cfg-export-master-key-hash/m-p/261560#M74156</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14291"&gt;@Rboehme&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's not how it works. If you don't know what the previous master key was set to at the time of the crash, it doesn't matter that you have the hash values. The hash values are created with the device's master key, so a hash value without the same master key in use is absolutely pointless as the system is unable to read it. The master key between the devices either need to match, or you will need to regenerate all passwords and keys.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2019 21:40:29 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-05-17T21:40:29Z</dc:date>
    <item>
      <title>cfg export + master key hash</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cfg-export-master-key-hash/m-p/261544#M74150</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found this side note in an article regarding the master key on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Without the Master Key, when a configuration is exported from a firewall, the password is hashed and can be copied."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically its the exact answer of the question I originally had. I am facing a situation where a firewall crashed. I have received the new firewall and have the certificates and the running config saved locally.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to import the config the firewall skips basically every entries in regards to password or keys and shows this as error messages. I do understand the firewall is unable to decrypt those data without a matching master key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However from &lt;STRONG&gt;where&amp;nbsp;&lt;/STRONG&gt;do I retrive the master key hash and do I assume correclty to use the hash as the password for the imported config?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rene&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 21:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cfg-export-master-key-hash/m-p/261544#M74150</guid>
      <dc:creator>Rboehme</dc:creator>
      <dc:date>2019-05-17T21:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: cfg export + master key hash</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cfg-export-master-key-hash/m-p/261560#M74156</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14291"&gt;@Rboehme&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's not how it works. If you don't know what the previous master key was set to at the time of the crash, it doesn't matter that you have the hash values. The hash values are created with the device's master key, so a hash value without the same master key in use is absolutely pointless as the system is unable to read it. The master key between the devices either need to match, or you will need to regenerate all passwords and keys.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 21:40:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cfg-export-master-key-hash/m-p/261560#M74156</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-17T21:40:29Z</dc:date>
    </item>
  </channel>
</rss>

