Configuring the Pre-shared Key

Note: Refer to Configuring MACsec for an overview of enabling and configuring MACsec features.

MACsec security is based on a pre-shared key, the Connectivity Association Key (CAK), which you define and name. Only MACsec-enabled interfaces that are configured with the same key can communicate over secure MACsec channels. The key can be configured directly on each MACsec interface, or you can configure a set of keys as an MKA keychain and apply the keychain to each interface. MKA keychain configuration is described in .
Note: Pre-shared key configuration and 'mka-keychain' configuration are not allowed on the same interface. If you have already configured and applied an MKA keychain to the MACsec interface, this task is not required.
  1. At the dot1x-mka-interface configuration level, enter the pre-shared-key command followed by the key-id, the keyword key-name, and a hex string to define and name the pre-shared key.
    The requirements for the parameters are as follows:
    • key-id: Define the key ID value using 32 hexadecimal characters.
    • key-name hex string: Give the key a name using from 2 through 64 hexadecimal characters (in 8-bit multiples).

In the following example, the pre-shared key with the hex value beginning with "135bd758b" and the key name beginning with "96437a93" are applied to interface 1/3/2.

device# configure terminal
device(config)# dot1x-mka  
device (config-dot1x-mka)# enable-mka ethernet 1/3/2
device(config-dot1x-mka-1/3/2)# pre-shared-key 135bd758b0ee5c11c55ff6ab19fdb199 key-name 96437a93ccf10d9dfe347846cce52c7d

Enable and configure each MACsec interface. Configure the same pre-shared key (CAK) on the interfaces between which a secure channel can be established.