Configuring a Keychain Module

Complete the following steps to configure keychain module.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Configure a keychain profile.
    device(config)# keychain ruckus
  3. (Optional) Configure the tolerance value for the keys.
    The following example configures a 10,000 second tolerance period for the keychain profile "ruckus."
    device(config-ruckus)# tolerance 10000
  4. Configure a key by specifying a key identifier.
    device(config-ruckus)# key-id 1
  5. Configure the authentication algorithm to be used for the key.
    Authentication algorithms HMAC-SHA-1, HMAC-SHA-256, MD5, SHA-1, and SHA-256 are supported. The application or protocol chooses the cryptographic algorithm that matches its criteria.
    The following example configures md5 as the authentication algorithm for key 1.
    device(config-ruckus-key-1)# authentication-algorithm md5
  6. Configure the password to be used for the key.
    device(config-ruckus-key-1)# password abc
  7. Configure the time period during which the key on a keychain is active and can be received as a valid key.
    The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).
    The following example configures the accept lifetime of key 1 to start on November 10, 2019 at 10:10 am and 10 seconds and to end 10,000 seconds later.
    device(config-ruckus-key-1)# accept-lifetime start 11-10-19 10:10:10 end 10000 
  8. Configure the time period during which the key on a keychain becomes active and is valid to be sent.
    The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).
    The following example configures key 1 to be active and available for sending from November 10, 2019 at 10:10 am and 10 seconds, with no expiration.
    device(config-ruckus-key-1)# send-lifetime start 11-10-19 10:10:10 end infinite