Creating and Configuring an MKA Keychain

Perform the following steps to configure an MKA keychain.

  1. In global configuration mode, enter the keychain command followed by the keychain name and the keyword mka.
    device# configure terminal
    device(config)# keychain sample mka
    device(config-keychain-mka-sample)#
    The keychain is created, and the device is placed in MKA keychain configuration mode.
  2. Configure the key identifier. Valid values are from 1 through 4294967296.
    device(config-keychain-mka-sample)# key-id 100
    The key is created, and the device is placed in MKA key configuration mode.
  3. Configure the authentication algorithm for the key. Options are authentication-algorithm aes-128-cmac and authentication-algorithm aes-256-cmac.
    Note: ICX 7450 devices support only AES-128-CMAC.
    device(config-keychain-mka-sample-key-100)# authentication-algorithm aes-128-cmac
  4. Configure the password for the key.
    Note: Passwords are composed of hexadecimal characters 0 through 9 and a through f. When AES-128-CMAC is used as the authentication algorithm, 16 hexadecimal characters must be configured. When AES-256-CMAC is used, 32 hexadecimal characters must be configured.
    device(config-keychain-mka-sample-key-100)# password 12345678123456781234567809abcdef12345678123456781234567809abcdef
  5. Configure the send-lifetime start and end times.
    Note: If you use the keywords end infinite as shown in the example instead of a specific end time, the key remains active indefinitely.
    device(config-keychain-mka-sample-key-100)# send-lifetime start 02-14-2022 01:01:01 end infinite
  6. (Optional) Configure the local timezone (as configured in the system) to be used for the start and end timers. If not configured, the lifetime values are based on the GMT clock time.
    device(config-keychain-mka-sample-key-100)# send life-time local
  7. (Optional) Configure the tolerance value for the keys.
    Note: Because of the potential for key overlap when the duration between the first key end-time and the following key start-time is short, RUCKUS recommends that you configure a minimum tolerance of 180 seconds to maintain hitless key rollover.
    The following example configures a 200 second tolerance period for the keychain profile "mka-sample-key-100."
    device(config-keychain-mka-sample-key-100)# tolerance 200

The following example creates the MKA keychain "sample" and configures the underlying options. The configured options are confirmed in the output of the show keychain name command.

device# configure terminal
device(config)# keychain sample mka
device(config-keychain-mka-sample)# key-id 100
device(config-keychain-mka-sample-key-100)# authentication-algorithm aes-128-cmac
device(config-keychain-mka-sample-key-100)# password 12345678123456781234567809abcdef12345678123456781234567809abcdef
device(config-keychain-mka-sample-key-100)# send-lifetime start 02-16-2022 04:05:00 end infinite
device(config-keychain-mka-sample-key-100)# tolerance 200
device(config-keychain-mka-sample-key-100)# end
device# show keychain name sample
Keychain: sample
  Tolerance: 0
  Key-id   : 100
      AuthAlgorithm: aes-128-cmac
      Key-String   : *******
      Send Lifetime:-
          Start    : 02-16-2022 04:05:00 End         : Infinite
          Active   : Yes                 TimeToExpire: Infinite
          Timezone : GMT+00
Next: Enable interfaces for MACsec, and apply the MKA group configuration and MKA keychain as described in Enabling and Configuring Group Interfaces for MACsec.