Configuring a Keychain Module
Complete the following steps to configure keychain module.
- Enter the
configure terminalcommand to enter global configuration mode. - Configure a keychain profile.
- (Optional) Configure the tolerance value for the keys.
The following example configures a 10,000 second tolerance period for the keychain profile "ruckus."
- Configure a key by specifying a key identifier.
- Configure the authentication algorithm to be used for the key.
Authentication algorithms HMAC-SHA-1, HMAC-SHA-256, MD5, SHA-1, and SHA-256 are supported. The application or protocol chooses the cryptographic algorithm that matches its criteria.The following example configures md5 as the authentication algorithm for key 1.
- Configure the password to be used for the key.
- Configure the time period during which the key on a keychain is active and can be
received as a valid key.
The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).The following example configures the accept lifetime of key 1 to start on November 10, 2019 at 10:10 am and 10 seconds and to end 10,000 seconds later.
- Configure the time period during which the key on a keychain becomes active and is
valid to be sent.
The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).The following example configures key 1 to be active and available for sending from November 10, 2019 at 10:10 am and 10 seconds, with no expiration.