Components of a Keychain
A keychain consists of the following components:
- Keychain profile: Each keychain is identified by a user-configured profile name. A maximum of 64 keychains can be configured.
- Key (key identifier): Keys are added to the keychain profile by specifying key IDs.
Each key ID within a keychain has its own properties, such as a password, authentication
algorithm, send lifetime, and accept lifetime. A key is considered valid only if the
key lifetime has not expired, and the password and authentication algorithm are specified.
A maximum of 1024 keys can be configured across all the keychains.
For each protocol, the key ID must be within a valid range. For example, the valid range of key IDs for OSPFv2 is 1 through 255. The application that uses the keychain module can reject the key IDs that are outside the permitted range. However, the keychain module does not place any restrictions on key ID configuration.
- Authentication algorithm: Each key must have an authentication algorithm. The application or protocol chooses the cryptographic algorithm that matches its criteria. The following algorithms are supported:
- Password: Each key must have a password in encrypted form for the cryptographic algorithm.
- Lifetime of key: Each key in the keychain has send and accept lifetimes. A key is considered active if it is within a configured time range. The lifetime of the key also depends on the tolerance value.
- Tolerance: The tolerance value extends the lifetime of keys beyond the configured active lifetime. A key is considered valid even when it is in the tolerance period. If the tolerance value is configured, the start time of the key is advanced (start time minus tolerance), and the end time is moved further ahead (end time plus tolerance), unless the end time is set to be infinite.