keychain mka

Configures a keychain module specific to MACsec.
Syntax
keychain { name mka }
no keychain { name mka }
Command Default

By default, no keychain is defined.

Parameters
name
Names the keychain.
mka
Specifies that the keychain is a MACsec Key Agreement (MKA) keychain.
Modes

Global configuration mode

Usage Guidelines

Keychains are an alternative to configuring a single pre-shared key on each MACsec interface. Each key contains a pre-configured password, authentication algorithm, and a send lifetime configuration.

The no form of the command deletes the keychain.

A maximum of eight MKA keychains can be configured.

Each MKA keychain can hold up to 32 keys.

An MKA keychain is allowed as part of interface configuration when a pre-shared key is not configured on the interface.

Specification of a key under a keychain shall be the same between peers for establishing a secure MACSec connection.

For each key ID, a password, authentication-algorithm, and send-lifetime start and end time are configured. If the keywords end infinite are configured as shown in the example instead of a specific end time, the key remains active indefinitely.

The default timezone used for calculating start and end times is GMT. As an option, you can configure the MKA keychain to use local time as configured in the system.

Because of the potential for key overlap when the duration between the first key end-time and the following key start-time is short, RUCKUS recommends that you configure a minimum tolerance of 180 seconds to maintain hitless key rollover.

Examples

The following example creates the MKA keychain "macsec1" and configures the underlying options.

device# configure terminal
device(config)# keychain macsec1 mka
device(config-keychain-mka-macsec1)# key-id 1
device(config-keychain-mka-macsec1-key-1)# password ........
device(config-keychain-mka-macsec1-key-1)# authentication-algorithm aes-256-cmac
device(config-keychain-mka-macsec1-key-1)# send-lifetime start 02-14-2022 01:01:01 end infinite
device(config-keychain-mka-sample-key-100)# local
device(config-keychain-mka-sample-key-100)# tolerance 200
device(config-keychain-mka-macsec1-key-1)# end
device#
History
Release version Command history
09.0.10b This command was introduced.