# Spec property names that look like secrets but hold none: a setting about a
# password, a name, an id, a public certificate or key, or a BGP community.
# tests/test_redact.py: every secret-looking name in the bundled specs is hidden
# by core/redact.py or listed here after review.
CacheCredentialsForDays
ClearPassZoneCache
PasswordPrompt
SSHCipherMode
ServerCertificateValidation
StoreReversibleLocalUserPasswords
access_token_lifetime
access_token_lifetime_units
add_community
additional_cacerts
admin-password-alias
admin_sshkeys
ae_lacp_passive
airpass
airpass-profile
airpass-profile-id
allow_passwords
apple-cna-bypass
auth-key-null
auth-provider-x509-cert-url
auth_provisioning_require_client_cert
authentication-key-id
authentication-key-type
bpdu-bypass
bypass-cp-landing-page
bypass-list
bypass_auth_when_server_down
bypass_auth_when_server_down_for_unknown_client
bypass_auth_when_server_down_for_voip
bypass_cna
bypass_proxy
bypass_when_cloud_down
ca-cert
ca-certificate
cacert
cacerts
cacerts-download
cacerts_configs
cert
cert-cn-lookup
cert-key-type
cert-name
cert-type
cert-usage-assignment
cert-valid-days
certIssuerDer
certSerialNum
certSubjectDer
cert_cn
cert_expire_time
cert_expiry
cert_file
cert_filter_criteria
cert_issuer
cert_provider
cert_providers
cert_san_upn
cert_serial
cert_sign_request
cert_subject
cert_type
cert_usage
certificate
certificate-auth-username
certificate-authorization
certificate-body
certificate-group
certificate-lock-out
certificate-lock-out-time
certificateExpiryDate
certificate_auth
certificate_comparison
certificate_file
certificate_file_encoding
certificate_pem
certificate_request
certificate_sub_type
certificate_type
certificate_url
certificate_version
certified
certs
cipher-enable
cipher-suite
cipher-suites
ciphers
ciphers_category
clearpass
client-x509-cert-url
client_cert_CN
client_cert_expiry_date
client_certificate
client_certificate_auth
community
community-expanded
community-list
community-list-entry
community-list-name
community-list-name-community-type
community-list-operation
community-operation
community-standard
community-value-all
community-value-asnn
community-vlan
community_vlan_id
cp-certificate
delegate-url-intermediate-cert1
delegate-url-intermediate-cert2
delegate-url-intermediate-cert3
delegate-url-leaf-cert
delete-keycache
device-certificate
device_cert
digital_pass
disable-cipher-type
dot11r-key-duration
dot11r-ondemand-keyfetch
eap-identity-password-alias
eap-tls-cert
eap-tls-cert-type
elevationUncertainty
enable-token-caching
enable_local_keycaching
encryption-key-type
enforce_src_ips_for_tokens
exclude_community
expiring_certs
export_communities
ext-key-usage
extended-key-usage
field_password_caption
form_password_encryption
form_password_label
gateway-key-caching
guest_password_complexity
guest_password_disallowed
guest_password_disallowed_words
guest_password_minimum
has_certificate
has_compass
hash
hash-mask-length
hash_lookup_only
hash_url
hashedMacAddress
hashing
heldstate-bypass
hide_psks_created_by_other_admins
host-key-algorithm-enable
host-key-algorithms
idp-cert
idp_cert
idp_machine_cert_lookup_field
idp_user_cert_lookup_field
intermediate_ca_cert
iot-cert
ip-ecmp-hash-params
ip-ssh-rekey
ipv6-certification-mode
issue_cert
key-attribute
key-chain
key-hash
key-id
key-identifier
key-length
key-server-priority
key-size
key-trusted
key-type
key-usage
key-usage-restriction
keyManagement
key_file_encoding
key_id
key_idx
key_mgmt
key_type
key_usage
key_usage_extended
keycache-timeout
keychain
keypair
keywrap_enabled
keywrap_format
last_cert_cn
last_cert_expiry
last_cert_issuer
last_cert_serial
last_cert_subject
last_psk_id
last_psk_name
latitudeUncertainty
lciUncertainty
ldap_cacerts
ldap_client_cert
local-keyfetch
longitudeUncertainty
mad-passthrough
match-community
match-community-asn
match-community-list
match-extended-community-list
md-key-id
md-password-type
min-password-length
mpsk-cloud-auth
mpsk-local-profile
mpsks
multi_psk_only
multicast-key-rotation-period
multicast-keyrotation
multipath-hash-ipv4
multipath-hash-ipv6
no_private_as
oauth2_access_token_url
oauth2_token_url
openroaming_wba_client_cert
opp-key-caching
org_apitoken_name
override_cert_url
pass_apps
pass_fields
pass_locations
pass_reset_flow
pass_style
passerby
passerbyCount
passive
passive-interface-default
passive-mode
passname
passphrase-alias
passphrase-format
passphrase-list
passphraseCancel
passphraseError
passphraseLabel
passphraseMessage
passphraseSubmit
passphraseTitle
passphrase_enabled
passphrase_expire
passphrase_rules
passpoint
password-aging
password-aging-period
password-alert-before-expiry
password-authentication
password-auto-expire
password-complexity
password-expired-user-login-attempts
password-expiry-user-login-attempts-period
password-lock-out
password-lock-out-time
password-minimum-age
password-minimum-history
password-placeholder
password-policy
password-type
password-update-interval
passwordPolicy
password_attribute
password_complexity
password_disallowed_characters
password_disallowed_words
password_expiry_days
password_header
password_minimum_length
password_modified_time
password_policy
password_prohibit_repeated_chars
password_prohibit_user_id
password_prompt_regex
password_remember_history
password_servers
password_type
pending_cert
pending_cert_expiry
poe_passthrough
primary_clearpass_server_uuid
private-key-id
private-vlan
private-vlan-association
private-vlan-port-type
private-vlan-type
privateIpAddress
private_key_type
private_vlan_port_type
private_wlan
psk_id
psk_ids
psk_name
pskportal_id
pubkey-algorithms
pubkey-authentication
public_key_algorithm
public_key_format
radsec-client-cert
radsec-est-cert-profile
radsec-trusted-cacert-name
radsec-trusted-servercert-name
radsec-use-est-certificate
radsec_verify_cert
random_mpsk_length
random_mpsk_method
random_mpsk_picture
random_password_length
random_password_method
random_password_picture
refresh_token_lifetime
refresh_token_lifetime_units
rekey-time
rekey-volume
remove-private-as
repeat-password-check
responder-cert
root_ca_cert
rsa-key-length
sak-rekey-interval
secret-type
secret_id
secret_type
send-community
send-community-enable
server-cert
server-certificate
server_cert
service_cert_cn
service_cert_expiry_date
serviceos-password-prompt
set-community
set-community-list
set-extended-community
sha-password-type
signer-cert
sitekey
ssh_keys
sso_idp_cert
standby_clearpass_server_uuid
subject_keyid
token-caching-period
token-uri
token-url
token_type
trusted-certificate
trusted_certificate_id
tunnel-private-group-id
two_factor_passed
uncertainty
unicast-key-rotation-period
unicast-keyrotation
url-hash-key-format
use_sso_role_for_cert
use_sso_role_for_psk_role
user_certificate
validate-server-cert
validate_cert
validate_url_cert
verify_cert
verify_server_certificate
vestaPasswordMethod
vestaPasswordParameter
via-client-cert-port
vpn-client-ca-certificate
vpn-server-certificate
wba_cert
wep-key-index
wep-key-retries
wep-key-size
wpa-groupkey-delay
wpa-key-period
wpa-key-retries
wpa-passphrase-alias
wpa2-key-delay
