authentication-algorithm (MKA)

Specifies the cryptographic algorithm to be used for the specified key in the MKA (MACsec) keychain.
Syntax
authentication-algorithm { aes-128-cmac | aes-256-cmac }
no authentication-algorithm { aes-128-cmac | aes-256-cmac }
Command Default

An authentication algorithm is not specified by default.

Parameters
aes-128-cmac
Sets the authentication algorithm to AES-128-CMAC.
aes-256-cmac
Sets the authentication algorithm to AES-256-CMAC.
Modes

MKA Key ID configuration mode

Usage Guidelines

The no form of the command removes the authentication algorithm from the key.

A key is considered valid only if the key has not expired and the password and authentication algorithm have been specified.

Examples

The following example configures the MKA keychain "fi-msec" to use key-10, which uses the authentication algorithm AES-128-CMAC. It then enables MACsec on interface 2/1/23 and applies the predefined MKA configuration group 4 and the MKA keychain "fi-msec" to the interface.

device# configure terminal
device(config)# keychain fi-msec mka
device(config-keychain-fi-msec)#key-id key-10
device(config-keychain-fi-msec-key-10)# password 2 $ITJkQG4hMmRAbiEyZEBuITJkQG5aWlpaWlpaWlpaWlo=
device(config-keychain-fi-msec-key-10)# authentication-algorithm aes-128-cmac <---
device(config-keychain-fi-msec-key-10)# send-lifetime start 11-10-2021 08:12:30 end 3600
device(config-keychain-fi-msec-key-10)# end

device# configure terminal
device(config)# enable-mka ethernet 2/1/23
device(config-dot1x-mka-2/1/23)# mka-cfg-group 4
device(config-dot1x-mka-2/1/23)# mka-key-chain fi-msec <----
device(config-dot1x-mka-2/1/23)# end
device#
History
Release version Command history
09.0.10b This command was introduced.