Password Hashing in Palo Alto Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Password Hashing in Palo Alto Firewall

L1 Bithead

Hi All,

 

Just wondering if palo Alto default password hashing and it would be great if there was a document regarding this. This is to meet and justify the audit requirement in that, the paloAlto are built with hashing method while login the account.

8 REPLIES 8

Cyber Elite
Cyber Elite

Hi @AinulSafiah ,

 

Here is your doc.  https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/configure-the-maste...

The default master key works fine, but it is a best practice to change it.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

Hello,

I agree with @TomYoung , please change the master password as there was a vulnerability for it a while back.

Regards,

Cyber Elite
Cyber Elite

Palo admin account passwords are hashed so they can't be reverted back to original passwords.

 

On the other hand accounts where Palo needs to connect somewhere (IPSec tunnels, LDAP etc) are encrypted using master key.

As master key has leaked it is possible for someone who is able to export your firewall config to decrypt credentials and gain access to PSK's or domain passwords.

 

Be careful to keep track of changed master key expiry date because if it expires your environment will go down.

"You must configure a new master key before the current key expires. If the master key expires, the firewall or Panorama automatically reboots in Maintenance mode. You must then Reset the Firewall to Factory Default Settings."

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/certificate-management/configure-the-mast...

 

Raido_Rattameister_0-1692430509706.png

 

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L1 Bithead

Hi all,

Thank you for your kind feeback. So to summarize it is confirmed that by default the password were in hash  

Cyber Elite
Cyber Elite

Hi @AinulSafiah ,

 

Yes, the NGFW by default encrypts all passwords and private keys.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi @TomYoung , mind if you could share us the documentation to support this statement?  Or this already included in this documentation https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/configure-the-maste... 

Cyber Elite
Cyber Elite

Hi @AinulSafiah ,

 

Yes, the 1st paragraph of that document states "Every firewall and Panorama management server has a default master key that encrypts all the private keys and passwords in the configuration to secure them (such as the private key used for SSL Forward Proxy Decryption)."

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L0 Member

Hi Ainul, can you explain more of this issue? Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!