Generating a DSA or RSA Key Pair

A command to generate a host key pair places the key pair in flash memory and enables SSH on the ICX device, if it is not already enabled.

Note: DSA encryption is deprecated in OpenSSH client versions 7.0 and later. Password authentication may be required.
  1. To generate an RSA key pair, enter the crypto key generate rsa command as shown in the following example.
    device# configure terminal
    device(config)# crypto key generate rsa
    
    The previous example generates an RSA key with the default modulus of 1024 bits. To generate a modulus 2048 key, enter the following command.
    device# configure terminal
    device(config)# crypto key generate rsa modulus 2048
    
  2. To generate a DSA key pair, enter the following command.
    device(config)# crypto key zeroize dsa
    
    The dsa keyword specifies a DSA host key pair. This keyword is optional. If you do not enter it, the command crypto key generate generates a DSA key pair by default.