SSH Rekey Exchange

In SSH2 implementation, if an SSH session is authenticated and established, the session remains connected until the user closes it or until it is closed after the configured idle time limit. Prolonged usage of the session key negotiated at connection startup poses several security issues and exposes SSH connections to man-in-middle attacks. To safeguard existing SSH connections from security vulnerabilities, new keys should be exchanged frequently.

SSH rekeying is the process of exchanging the session keys at a configured interval, based on a time limit or a data limit for the SSH session. SSH rekeying is triggered when the time limit (maximum minutes) or the data limit has been reached for the session. Rekey can be initiated by either the client or the server. While the key exchange renegotiation is taking place, data does not pass through the SSH connection. The algorithm that was used at connection startup is used during rekey.

In CC mode, the SSH rekey feature is enabled by default and cannot be disabled. The default value for time is 30 minutes, and the default limit for data is 500MB (500,000 KB) in CC mode. If the rekey configuration is removed CC mode, the default values are applied. The default values are not displayed in the configuration.

Note: To remain in compliance with Korean CC requirements, the rekey limits must be kept under one hour and 1 Gigabyte.

SSH Rekey Configuration Notes

  • The encryption method must not be modified during the rekey process.
  • When the rekey configuration has changed, the change has no impact on the existing session until the next rekey exchange for the session occurs.
  • When a rekey exchange occurs, the value of data and time for the corresponding SSH session is reset to the configured rekey value.
  • SSH sessions established without rekey configuration do not have the rekey functionality.
  • When rekey is enabled, the existing SSH session does not have the rekey functionality until the rekey exchange occurs from the other side.
  • When the rekey configuration is removed, the default values are applied.

SSH Rekey Configuration Examples

The following example configures rekeying of the outbound SSH session every hour.

device# configure terminal
device(config)# ip ssh rekey client time 60

The following example configures rekeying on the inbound SSH session whenever 10,000 Kilobytes of data are transmitted.

device# configure terminal
device(config)# ip ssh rekey server data 10000

The following example resets SSH rekey exchange to default settings (and does not disable the function). The defaults can be restored from either the client or the server side.

device# configure terminal
device(config)# no ip ssh rekey client time 60

Syntax: ip ssh rekey { client | server } { data Kbytes | time minutes }

Syntax: no ip ssh rekey { client | server } { data Kbytes | time minutes }