MKA Keychain Overview and Considerations

Keychains are an alternative to configuring a single pre-shared key on each MACsec interface. You can configure a maximum of eight MKA keychains, and each keychain can contain a maximum of 32 configured keys. Each key contains a pre-configured password, authentication algorithm, and a send lifetime configuration.

Keep the following considerations in mind when configuring MKA keychains.

  • When you use the keychain feature for a MACsec interface, the authentication algorithm configured under mka-keychain is used. The authentication algorithm configured under mka-cfg-group is not used.
  • An MKA keychain cannot be modified after it is bound to an interface.
  • An MKA keychain does not support a combination of AES-128 and AES-256 algorithms. Only one of the two algorithms can be configured in the same keychain.
  • The 'accept-lifetime' configuration under the keychain module configuration does not apply to the MACsec keychain.
  • The interval between Start and End lifetime for a configured MKA key must be a minimum of 120 seconds.
  • The interval between activation of two successive MKA keys must be a minimum of 120 seconds.
  • All invalid keys in the MKA keychain will be ignored.
  • ICX devices do not support hitless key-rollover of MACsec sessions across keychains with different cryptographic key sizes (for example, 128 bits to 256 bits or vice versa).