authentication-algorithm (MKA)
authentication-algorithm
{
aes-128-cmac
|
aes-256-cmac
}no
authentication-algorithm
{
aes-128-cmac
|
aes-256-cmac
}An authentication algorithm is not specified by default.
MKA Key ID configuration mode
The no form of the command
removes the authentication algorithm from the key.
A key is considered valid only if the key has not expired and the password and authentication algorithm have been specified.
The following example configures the MKA keychain "fi-msec" to use key-10, which uses the authentication algorithm AES-128-CMAC. It then enables MACsec on interface 2/1/23 and applies the predefined MKA configuration group 4 and the MKA keychain "fi-msec" to the interface.
device# configure terminal device(config)# keychain fi-msec mka device(config-keychain-fi-msec)#key-id key-10 device(config-keychain-fi-msec-key-10)# password 2 $ITJkQG4hMmRAbiEyZEBuITJkQG5aWlpaWlpaWlpaWlo= device(config-keychain-fi-msec-key-10)# authentication-algorithm aes-128-cmac <--- device(config-keychain-fi-msec-key-10)# send-lifetime start 11-10-2021 08:12:30 end 3600 device(config-keychain-fi-msec-key-10)# end device# configure terminal device(config)# enable-mka ethernet 2/1/23 device(config-dot1x-mka-2/1/23)# mka-cfg-group 4 device(config-dot1x-mka-2/1/23)# mka-key-chain fi-msec <---- device(config-dot1x-mka-2/1/23)# end device#
| Release version | Command history |
|---|---|
| 09.0.10b | This command was introduced. |