crypto key generate
crypto key
generate
[
rsa
[
label
label_name
modulus
key-size
|
modulus
key-size
]
]crypto key
generate
[
ec
label
label_name
[
size
bit_value
]
|
size
bit_value
]
A crypto key is not generated, and SSH is not enabled.
Global configuration mode
To enable SSH, generate an RSA or ECDSA host key on the device. The SSH server on the ICX device uses this host RSA or ECDSA key to negotiate a session key and encryption method with the client trying to connect to it. While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions. When a host key is generated, it is saved to the flash memory. The time to initially generate SSH keys varies depending on the configuration, and can be from a under a minute to several minutes.
To disable SSH, delete all of the host keys from the device. When a host key is deleted, it is deleted from the flash memory.
An RSA key with modulus 2048 or greater must be used in FIPS or Common Criteria mode.
An RSA key with modulus 3000 or greater must be used in BSI Cloud mode.
In BSI Cloud mode, enabled with the bsicloud enable
command, RSA modulus 2048 cannot be used.
The following example generates a client RSA key pair with a modulus size of 2,048 bits.
device# configure terminal device(config)# crypto key generate rsa modulus 2048