Deleting ECDSA and RSA Key Pairs

You can delete both ECDSA and RSA key pairs with the crypto key zeroize command, or you can specify a key pair to be deleted. When a host key is deleted, it is deleted from the flash memory of all management modules. If all key pairs are removed from the flash memory, SSH will get disabled.

To delete both ECDSA and RSA key pairs from the flash memory, complete the following steps:

  1. Enter global configuration mode.
    device# configure terminal
  2. Delete both ECDSA and RSA key pairs from the flash memory.
    device(config)# crypto key zeroize
    You can also specify a key pair if you want to delete only a particular key pair.

    To delete the RSA host key pair from flash memory, enter the following command.

    device(config)# crypto key zeroize rsa
    

    To delete the ECDSA host key pair from flash memory, enter the following command.

    device(config)# crypto key zeroize ec
    
The following example shows the steps to generate ECDSA key pair, make an outbound connection from VM(Linux) to the device using ECDSA 384 bit, and delete the keys.
  1. Generate an ECDSA key pair.
    device(config)# crypto key generate ec size 384
    
  2. After the key is generated successfully, make an inbound connection from VM (Linux) to the device with configured local user or remote user.
    1. Connect to the Management IP.
      root@iaas-l-82:~# ssh -o HostKeyAlgorithms=ecdsa-sha2-nistp384 super@10.176.156.48
      Password:
      SSH@ICX7x50 Router>
    2. Connect to the Management IP.
      root@iaas-l-82:~# ssh -o HostKeyAlgorithms=ecdsa-sha2-nistp384 super@10.176.156.48
      Password:
      ~ #
  3. Delete all host key pairs.
    device(config)# crypto key zeroize