keychain mka
By default, no keychain is defined.
Global configuration mode
Keychains are an alternative to configuring a single pre-shared key on each MACsec interface. Each key contains a pre-configured password, authentication algorithm, and a send lifetime configuration.
The no form of the command
deletes the keychain.
A maximum of eight MKA keychains can be configured.
Each MKA keychain can hold up to 32 keys.
An MKA keychain is allowed as part of interface configuration when a pre-shared key is not configured on the interface.
Specification of a key under a keychain shall be the same between peers for establishing a secure MACSec connection.
For each key ID, a password, authentication-algorithm, and send-lifetime start and end time are configured. If the keywords end infinite are configured as shown in the example instead of a specific end time, the key remains active indefinitely.
The default timezone used for calculating start and end times is GMT. As an option, you can configure the MKA keychain to use local time as configured in the system.
Because of the potential for key overlap when the duration between the first key end-time and the following key start-time is short, RUCKUS recommends that you configure a minimum tolerance of 180 seconds to maintain hitless key rollover.
The following example creates the MKA keychain "macsec1" and configures the underlying options.
device# configure terminal device(config)# keychain macsec1 mka device(config-keychain-mka-macsec1)# key-id 1 device(config-keychain-mka-macsec1-key-1)# password ........ device(config-keychain-mka-macsec1-key-1)# authentication-algorithm aes-256-cmac device(config-keychain-mka-macsec1-key-1)# send-lifetime start 02-14-2022 01:01:01 end infinite device(config-keychain-mka-sample-key-100)# local device(config-keychain-mka-sample-key-100)# tolerance 200 device(config-keychain-mka-macsec1-key-1)# end device#
| Release version | Command history |
|---|---|
| 09.0.10b | This command was introduced. |