Encrypted-credentials mode
As CAK is a key and needs to be protected, when in encrypt-credentials mode the value gets encrypted and stored in the configuration.
Syntax
[no] mode pre-shared-key ckn <CKN> encrypted-cak <ENC-CAK>
Configure the CA Key (CAK) of this MACsec policy in encrypted form. A CAK must be specified before the policy can be applied. The value is an encrypted string previously read from a compatible Networking device.