219
• The plaintext form of the key in non-FIPS mode is a string of 1 to 64 characters. The plaintext
form of the key in FIPS mode is a string of 15 to 64 characters, which must contain numbers,
uppercase letters, lowercase letters, and special characters.
• The length of the encrypted from of the key varies by authentication algorithm and key string
format, as shown in Table 4 4 .
Table 44
Length requirements for authentication keys in encrypted form
Authentication
algorithm
Hexadecimal string Non-hexadecimal string
MD5 32 characters 53 characters
SHA 40 characters 57 characters
privacy-mode: Specifies an encryption algorithm for privacy. The encryption algorithms AES, 3DES,
and DES are in descending order of security strength. DES is enough to meet general security
requirements.
• aes128: Specifies the AES algorithm.
• 3des: Specifies the 3DES algorithm.
• des56: Specifies the DES algorithm.
priv-password: Specifies the privacy key. This argument is case sensitive.
• The plaintext form of the key in non-FIPS mode is a string of 1 to 64 characters. The plaintext
form of the key in FIPS mode is a string of 15 to 64 characters, which must contain numbers,
uppercase letters, lowercase letters, and special characters.
• The length of the encrypted from of the key varies by authentication algorithm and key string
format, as shown in Table 4 5 .
Table 45
Length requirements for privacy keys in encrypted form
Authentication
algorithm
Encryption
algorithm
Hexadecimal string Non-hexadecimal string
MD5 3DES 64 characters 73 characters
MD5
AES128 or
DES-56
32 characters 53 characters
SHA 3DES 80 characters 73 characters
SHA
AES128 or
DES-56
40 characters 53 characters
acl: Specifies a basic IPv4 ACL for the user.
ipv4-acl-number: Specifies a basic IPv4 ACL by its number in the range of 2000 to 2999.
name ipv4-acl-name: Specifies a basic IPv4 ACL for the user. The ipv4-acl-name argument
represents a basic IPv4 ACL name, a case-insensitive string of 1 to 63 characters.
acl ipv6: Specifies a basic IPv6 ACL for the user.
ipv6-acl-number: Specifies a basic IPv6 ACL by its number in the range of 2000 to 2999.