sk182339 - Gaia gClish saves the Expert mode password hash as MD5 although SHA method was configured on a Security Group
Gaia gClish saves the Expert mode password hash as MD5 although SHA method was configured on a Security Group
Product: Maestro HyperScale Firewall, Scalable Chassis
Version: R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2026-05-26
Symptoms
- Although an SHA hash type was configured for Gaia OS passwords with the Gaia Global Clish command
set password-controls password-hash-type, the Gaia Global Clish commandset expert-passwordsaves the password as an MD5 hash in the Gaia OS database. - On each Security Group Member, the Gaia Clish command
set expert-passwordsaves the password as an expected SHA hash.
Cause
Due to the current design, the Gaia Global Clish always saves the password as an MD5 hash in the Gaia OS database.
Solution
This problem was fixed. The fix is included starting from:
- Check Point Quantum R82.10
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 126
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-06-17
Last Modified: 2026-05-26