tolerance

Configures the tolerance value for the accept keys and send keys for the keychain to extend the lifetime of the keys beyond the active lifetime duration (prior to the start of the lifetime or after the end of the lifetime).
Syntax
tolerance value
no tolerance value
Parameters
value
Specifies the tolerance duration in seconds. The valid range is from 1 through 8640000 seconds.
Modes

Keychain configuration mode

Usage Guidelines

If the tolerance value is configured, the start time of the key to become active is advanced (start time minus tolerance) and the end time is moved further ahead (end time plus tolerance) before the key expires, unless the end time is set to be infinite.

A key is considered valid when it is in the tolerance period.

The no form of the command removes the tolerance value added to all the keys under the keychain.

Examples

The following example configures the keychain with a tolerance value of 600 seconds (10 minutes).

device# configure terminal
device(config)# keychain xprotocol
device(config-keychain-xprotocol)# tolerance 600
History
Release Command History
08.0.70 This command was introduced.