Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How a user's password being stored? Encryption algo/key length/hashing algo?

Greetings,

We currently own two Sophos XG firewall, model XG-135 & XG-210 and was wondering on how the passwords are being stored? Is there a pdf document or website link that we can refer to for our references? This question was query by our auditor, and currently we are still not sure how to find this information.

Original Question, "how firewall user's password are being stored.. encryption algo/key length/hashing algo?"

Best regards,
SDZ



This thread was automatically locked due to age.
Parents
  • Actually they are not stored, as far as i know. We only take the sent hash of the client, forward them to the service controller (AD) and work with the results. We perform this each and every time. Do you need a official statement about this, then contact support. 

Reply
  • Actually they are not stored, as far as i know. We only take the sent hash of the client, forward them to the service controller (AD) and work with the results. We perform this each and every time. Do you need a official statement about this, then contact support. 

Children
No Data