crypto key client generate

Generates the crypto client key to enable SSH2.
Syntax
crypto key client generate { dsa | rsa [ modulus key-size ] }
Command Default

The crypto client key is not generated and SSH2 is not enabled.

Parameters
dsa
Generates a DSA client key pair.
rsa
Generates an RSA client key pair.
modulus key-size
Specifies the modulus size of the RSA key pair, in bits. The valid values for the modulus size are 1024 or 2048. The default value is 1024.
Modes

Global configuration mode

Usage Guidelines

The dsa keyword is optional. If you do not enter the dsa keyword, the crypto key generate command generates a DSA key pair by default.

To use the SSH client for public key authentication, you must generate SSH client authentication keys and export the public key to the SSH servers to which you want to connect.

To disable SSH, you delete all of the client keys from the device. When a client key is deleted, it is deleted from the flash memory of all management modules.

An RSA key with modulus 2048 must be used in FIPS or Common Criteria mode.

Examples

The following example shows how to generate the DSA client key pair.

device(config)# crypto key client generate dsa

The following example shows how to generate the RSA key pair.

device(config)# crypto key client generate rsa modulus 2048