Community discussions

MikroTik App
 
someone2
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Sun Jan 07, 2018 9:52 pm

What is sensitive

Sun Mar 28, 2021 8:03 am

Hello
What is sensitive policy in mikrotik for user groyps?
What is regarded as sensitive in mikrotik? Is there a complete list?
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: What is sensitive

Sun Mar 28, 2021 9:12 am

The list is quite brief. passwords (e.g. in /ppp secret rows), passphrases (e.g. in wireless/capsman security profiles), and secrets (in IPsec identities) are "sensitive". Usernames, public IP addresses, MAC addresses, and serial numbers are not treated as "sensitive". Nor is anything in scripts.

Passwords of user accounts (those you use to log in to Mikrotik itself) are "write-only", they are never shown or exported.
 
bbs2web
Member Candidate
Member Candidate
Posts: 232
Joined: Sun Apr 22, 2012 6:25 pm
Location: Johannesburg, South Africa
Contact:

Re: What is sensitive

Wed Jan 11, 2023 5:52 pm

Is there an official list available somewhere? I would for example like to know whether the change in behaviour or bug is a security issue. The following script for example periodically resolves DNS FQDNs and then updates configured RADIUS authentication servers:
/radius set [find comment=radius1:] address=[:resolve radius1.redacted.com];
/radius set [find comment=radius2:] address=[:resolve radius2.redacted.com];


RouterOS 7 requires the following policies:
  • read
  • write
  • test
  • policy

RouterOS 6 works with the above or the following policies:
  • read
  • write
  • test
  • sensitive

Is anyone aware of a Wiki article that possibly details these policies?

Who is online

Users browsing this forum: No registered users and 125 guests