crypto key generate

Generates the crypto key to enable SSH.
Syntax
crypto key generate [ rsa [ label label_name modulus key-size | modulus key-size ] ]
crypto key generate [ ec label label_name [ size bit_value ] | size bit_value ]
Command Default

A crypto key is not generated, and SSH is not enabled.

Parameters
rsa
Generates the RSA host key pair.
label label_name
Specifies a RSA key pair label.
modulus key-size
Specifies the modulus size of the RSA key pair, in bits. The valid values for the modulus size are 2048, 3072 (the default), and 4096.
ec label label_name
Generates and names an elliptic-curve cryptography key pair.
size bit_value
Specifies the size of the elliptic-curve cryptography key pair in bits. The supported values are 256, 384, and 521. The default is 384 bits.
Modes

Global configuration mode

Usage Guidelines

To enable SSH, generate an RSA or ECDSA host key on the device. The SSH server on the ICX device uses this host RSA or ECDSA key to negotiate a session key and encryption method with the client trying to connect to it. While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions. When a host key is generated, it is saved to the flash memory. The time to initially generate SSH keys varies depending on the configuration, and can be from a under a minute to several minutes.

To disable SSH, delete all of the host keys from the device. When a host key is deleted, it is deleted from the flash memory.

An RSA key with modulus 2048 or greater must be used in FIPS or Common Criteria mode.

An RSA key with modulus 3000 or greater must be used in BSI Cloud mode.

In BSI Cloud mode, enabled with the bsicloud enable command, RSA modulus 2048 cannot be used.

Examples

The following example generates a client RSA key pair with a modulus size of 2,048 bits.

device# configure terminal
device(config)# crypto key generate rsa modulus 2048

The following example generates an elliptic-curve cryptography key pair named testkey with the default size of 384 bits.

device# configure terminal
device(config)# crypto key generate ec label testkey
History
Release version Command history
09.0.00 This command has been modified to remove the modulus 1024 option and make modulus 2048 the default. The dsa keyword was removed.
09.0.10b This command was modified to support ECDSA.
10.0.10c This command was modified to add larger RSA key sizes. The RSA modulus key size default also changes from 2048 to 3072.