SSH Rekey Exchange

In SSH2 implementation, if an SSH session is authenticated and established, the session remains connected until the user closes it or until it is closed after the configured idle time limit. Prolonged usage of the session key negotiated at connection startup poses several security issues and exposes SSH connections to man-in-middle attacks. To safeguard existing SSH connections from security vulnerabilities, new keys should be exchanged frequently.

SSH rekeying is the process of exchanging the session keys at a configured interval, based on a time limit or a data limit for the SSH session. SSH rekeying is triggered when the time limit (maximum minutes) or the data limit has been reached for the session. Rekey can be initiated by either the client or the server. While the key exchange renegotiation is taking place, data does not pass through the SSH connection. The algorithm that was used at connection startup is used during rekey.

In FIPS and CC modes, the SSH rekey feature is enabled by default and cannot be disabled. The default value for time is 30 minutes, and the default limit for data is 500 Mbytes in both FIPS and CC modes. If the rekey configuration is removed in either FIPS or CC mode, the default values are applied. The default values are not displayed in the configuration.

When moving from non-FIPS mode to FIPS/CC mode:, if SSH rekey is enabled in non-FIPS mode, the configured values are applied while moving to FIPS mode. If SSH rekey is not configured in non-FIPS mode, the default values in FIPS and CC mode will be applied.

In transitioning from FIPS or CC mode to non-FIPS mode, the SSH rekey configuration is removed, and the feature is disabled in non-FIPS mode.

SSH Rekey Configuration Notes

  • The encryption method must not be modified during the rekey process.
  • When rekey configuration has changed, the change has no impact on the existing session until the next rekey exchange for the session occurs.
  • When a rekey exchange occurs, the value of data and time for the corresponding SSH session is reset to the configured rekey value.
  • SSH sessions established without rekey configuration do not have the rekey functionality.
  • When rekey is enabled, the existing SSH session does not have the rekey functionality until the rekey exchange occurs from the other side.
  • When the rekey configuration is removed, the default values are applied.

SSH Rekey Configuration Examples

The following example configures rekeying of the outbound SSH session every hour.

device# configure terminal
device(config)# ip ssh rekey client time 60

The following example configures rekeying on the inbound SSH session whenever 10,000 Kilobytes of data are transmitted.

device# configure terminal
device(config)# ip ssh rekey server data 10000

The following example resets SSH rekey exchange to default settings (and does not disable the function). The defaults can be restored from either the client or the server side.


device# configure terminal
device(config)# no ip ssh rekey client time 60

Syntax: ip ssh rekey { client | server } { data Kbytes | time minutes }

Syntax: no ip ssh rekey { client | server } { data Kbytes | time minutes }