crypto key generate
crypto key
generate
[
dsa
|
rsa
[
modulus
key-size
]
]
crypto key
generate
{
ec
label
label_name
[
size
{
256
|
384
}
]
}
A crypto key is not generated and SSH is not enabled.
Global configuration mode
The dsa keyword is optional. If you do not enter the dsa keyword, the crypto key generate command generates a DSA key pair by default.
To enable SSH, you generate a DSA or RSA host key on the device. The SSH server on the ICX device uses this host DSA or RSA key, along with a dynamically generated server DSA or RSA key pair, to negotiate a session key and encryption method with the client trying to connect to it. While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions. When a host key is generated, it is saved to the flash memory of all management modules. The time to initially generate SSH keys varies depending on the configuration, and can be from a under a minute to several minutes.
To disable SSH, you delete all of the host keys from the device. When a host key is deleted, it is deleted from the flash memory of all management modules.
An RSA key with modulus 2048 must be used in FIPS or Common Criteria mode.