show keychain

Displays keychain-related configuration and status information.
Syntax
show keychain [ resource | tcp | mka | name keychain-name [ key-id | active ] ]
Parameters
resource
Displays the number of keychains configured, the status of the keychain timer, and the number of keys configured currently.
tcp
Displays configuration information only for TCP authentication (AO) keychains.
mka
Displays configuration information only for MKA (MACsec) authentication keychains.
name keychain-name
Displays the keychain configuration details of a specific keychain.
key-id
Displays the details of a specific key within a keychain.
active
Displays the active keys under a specific keychain.
Modes

User EXEC mode

Privileged EXEC mode

Global configuration mode

Keychain configuration mode

Key ID configuration mode

Examples

The following example displays keychain configuration details.

device# show keychain

Keychain  : 1
Tolerance : 36000
--------------------------------------------------------------------------------------------------------
KeyId | Algorithm | SendId | RecvId | SendActive|SendTimer|AcceptActive|AcceptTimer|AoMismatch|TcpOption
--------------------------------------------------------------------------------------------------------
1     aes-128-cmac  100      100     Yes(Local)   82259    Yes(Local)   118259      YES        YES   
2     hmac-sha-1      2        2     No (Local)   47159    No (Local)    47159      YES        YES   

Keychain  : 2
Tolerance : 36000
-------------------------------------------------------------------------------------------------------
KeyId | Algorithm |SendId | RecvId | SendActive|SendTimer|AcceptActive|AcceptTimer|AoMismatch|TcpOption
-------------------------------------------------------------------------------------------------------
1     aes-128-cmac 100      100     Yes(Local)   82259    Yes(Local)   118259      YES        YES   
2     hmac-sha-1     2        2     No (Local)   47159    No (Local)    47159      YES        YES  

The following example displays the number of keychains configured, the status of the keychain timer, and the number of keys configured currently.

device# show keychain resource  
Total Keychains Configured: 1
Keychain Timer Operational: Yes
Keychain Resource Infromation:-
                      alloc in-use  avail get-fail    limit  get-mem  size init
Keychain                 64      1     63        0       64        1   339   64
Key                     256      2    254        0     1024        2   983  256
Misc                     64      0     64        0      128        0    16   64

The following example displays the keychain configuration details of a specific keychain.

device# show keychain name 1    
Keychain: 1
  Tolerance: 36000
  TCP-AO: TRUE
  Key-id   : 1
      AuthAlgorithm: aes-128-cmac
      Key-String   : *******
      Send-id : 100
      Recv-id : 100
      Include_tcp_options : YES
      Accept-ao-mismatch  : YES
      Send Lifetime:-
          Start    : 09-09-2021 00:01:00 End         : 09-10-2021 12:15:00
          Active   : Yes                 TimeToExpire: 82167 sec
          Timezone : Local 
      Accept Lifetime:-
          Start    : 09-09-2021 00:01:00 End         : 09-10-2021 12:15:00
          Active   : Yes                 TimeToExpire: 118167 sec
          Timezone : Local
  Key-id   : 2
      AuthAlgorithm: hmac-sha-1
      Key-String   : *******
      Send-id : 2
      Recv-id : 2
      Include_tcp_options : YES
      Accept-ao-mismatch  : YES
      Send Lifetime:-                                             
          Start    : 09-10-2021 12:30:00 End         : 09-15-2021 20:55:00
          Active   : No                  TimeToActive: 47067 sec
          Timezone : Local 
      Accept Lifetime:-
          Start    : 09-10-2021 12:30:00 End         : 09-15-2021 20:55:00
          Active   : No                  TimeToActive: 47067 sec

The following example displays the details of a specific key by specifying the key ID within a keychain.

device# show keychain name 1 1
Keychain: 1
  Tolerance: 36000
  TCP-AO: TRUE
  Key-id   : 1
      AuthAlgorithm: aes-128-cmac
      Key-String   : *******
      Send-id : 100
      Recv-id : 100
      Include_tcp_options : YES
      Accept-ao-mismatch  : YES
      Send Lifetime:-
          Start    : 09-09-2021 00:01:00 End         : 09-10-2021 12:15:00
          Active   : Yes                 TimeToExpire: 82128 sec
          Timezone : Local 
      Accept Lifetime:-
          Start    : 09-09-2021 00:01:00 End         : 09-10-2021 12:15:00
          Active   : Yes                 TimeToExpire: 118128 sec
          Timezone : Local

The following example displays the active keys under the "ruckus" keychain.

device# show keychain name ruckus active
Keychain: ruckus
 TCP-AO: TRUE
Key-id   : 1
 Auth-Algorithm: hmac-sha-1
    Key-String : *******
    Send-id : 1
    Recv-id : 1
    include-tcp-options : YES
    accept-ao-mismatch : YES
    Send Lifetime:-
    Start : 12-04-2021 11:11:11 End : 12-04-2022 11:11:11
    Active : No TimeToActive: 27583321 sec
    Timezone : Local
    Accept Lifetime:-
    Start : 12-04-2021 11:11:11 End : 12-04-2022 11:11:11
    Active : No TimeToActive: 27583321 sec
    Timezone : Local

The following example displays configuration information for TCP authentication keychains.

device# show keychain tcp

Keychain  : 1
Tolerance : 36000
------------------------------------------------------------------------------------------------------------------------
KeyId     |  Algorithm  | SendId | RecvId | SendActive | SendTimer | AcceptActive | AcceptTimer | AoMismatch | TcpOption
------------------------------------------------------------------------------------------------------------------------
1           aes-128-cmac    100      100    Yes(Local)   82233        Yes(Local)     118233           YES        YES   
2           hmac-sha-1      2        2      No (Local)   47133        No (Local)     47133            YES        YES   

Keychain  : 2
Tolerance : 36000
------------------------------------------------------------------------------------------------------------------------
KeyId     |  Algorithm  | SendId | RecvId | SendActive | SendTimer | AcceptActive | AcceptTimer | AoMismatch | TcpOption
------------------------------------------------------------------------------------------------------------------------
1           aes-128-cmac    100      100    Yes(Local)   82233        Yes(Local)     118233           YES        YES   
2           hmac-sha-1      2        2      No (Local)   47133        No (Local)     47133            YES        YES   

The following example shows information for MKA (MACsec) authentication keychains only. In the example, only one MKA keychain has been configured. The show keychain name command is used to display additional details.

device# show keychain mka

Keychain  : sample
Tolerance : 0
----------------------------------------------------------------------------
  Key-id  |    Algo    | SendActive | SendTimer | AcceptActive | AcceptTimer 
----------------------------------------------------------------------------
    100    aes-128-cmac  Yes(GMT+00)      -        No(GMT+00)          -

device# show keychain name sample
Keychain: sample
  Tolerance: 0
  Key-id   : 100
      AuthAlgorithm: aes-128-cmac
      Key-String   : *******
      Send Lifetime:-
          Start    : 02-16-2022 04:05:00 End         : Infinite
          Active   : Yes                 TimeToExpire: Infinite
          Timezone : GMT+00
History
Release Command History
08.0.70 This command was introduced.
09.0.10 This command was modified to add a TCP option.
09.0.10b This command was modified to add an MKA option.