# EIGRP SHA Authentication

**URL:** https://forum.networklessons.com/t/eigrp-sha-authentication/1347
**Category:** Lessons Discussion
**Created:** [December 29, 2016, 9:27pm UTC](https://forum.networklessons.com/t/eigrp-sha-authentication/1347 "2016-12-29T21:27:24Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [June 2, 2020, 6:20am UTC](https://forum.networklessons.com/t/eigrp-sha-authentication/1347/3 "2020-06-02T06:20:03Z")

</div>

Hello Matthew

What you state is very logical, it seems redundant to need to specify a password for the SHA-256 and then to need to specify a keychain password as well. However, this is the methodology used to configure SHA-256.

In order to specify a key-chain, you must first specify the authentication mode. And in order to specify the hmac-sha-256 mode, you must specify a password. (If you choose the MD5 method, you don’t specify a password, but you must employ the key-chain). If you choose to use the key-chain method, then once that is configured, the key-chain password supersedes the hmac-sha-256 password.

It’s just the way that the SHA-256 authentication has been designed. Cisco documentation actually seems to support not using the key-chain method, as the SHA-256 password is considered equally secure:

> **[IP Routing EIGRP Configuration Guide, Cisco IOS Release 15SY - EIGRP/SAF...](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_eigrp/configuration/15-sy/ire-15-sy-book/ire-sha-256.html)**
>
> IP Routing EIGRP Configuration Guide, Cisco IOS Release 15SY 
> -EIGRP/SAF HMAC-SHA-256 Authentication

I hope this has been helpful!

Laz

---

_[View the full topic](https://forum.networklessons.com/t/eigrp-sha-authentication/1347)._
