Components of a Keychain
Note: For different protocols, keychain options may vary as described under the specific
protocol.
A keychain consists of the following components:
- Keychain profile: Each keychain is identified by a user-configured profile name. A maximum of 64 keychains can be configured.
- Keys: Keys are added to the keychain profile by
specifying key IDs. Each key ID within a keychain has its own properties, such
as a password, authentication algorithm, send lifetime, and accept lifetime.
A
key is considered valid only if the key lifetime has not expired, and the
password and authentication algorithm are specified. A maximum of 1024 keys can
be configured across all the keychains.
For each protocol, the key ID must be within a valid range. For example, the valid range of key IDs for OSPFv2 is 1 through 255. The application that uses the keychain module can reject the key IDs that are outside the permitted range. However, the keychain module does not place any restrictions on key ID configuration.
- Authentication algorithm: Each key must have an authentication algorithm. The application or protocol chooses the cryptographic algorithm that matches its criteria. The following algorithms are supported:
- Password: Each key must have a password in encrypted form for the cryptographic algorithm.
- Lifetime of key: Each key in the keychain has send and accept lifetimes. A key is considered active if it is within a configured time range. The lifetime of the key also depends on the tolerance value.
- Tolerance: The tolerance value extends the lifetime of keys beyond the configured active lifetime. A key is considered valid even when it is in the tolerance period. If the tolerance value is configured, the start time of the key is advanced (start time minus tolerance), and the end time is moved further ahead (end time plus tolerance), unless the end time is set to be infinite.