Creating and Configuring an MKA Keychain
Perform the following steps to configure an MKA keychain.
- In global configuration mode,
enter the
keychaincommand followed by the keychain name and the keyword mka.The keychain is created, and the device is placed in MKA keychain configuration mode. - Configure the key identifier.
Valid values are from 1 through 4294967296.The key is created, and the device is placed in MKA key configuration mode.
- Configure the authentication
algorithm for the key. Options are
authentication-algorithm aes-128-cmacandauthentication-algorithm aes-256-cmac. - Configure the password for the
key.Note: Passwords are composed of hexadecimal characters 0 through 9 and a through f. When AES-128-CMAC is used as the authentication algorithm, 16 hexadecimal characters must be configured. When AES-256-CMAC is used, 32 hexadecimal characters must be configured.
- Configure the send-lifetime start and end times.Note: If you use the keywords end infinite as shown in the example instead of a specific end time, the key remains active indefinitely.
- (Optional) Configure the local timezone (as configured in the system) to be used for the start and end timers. If not configured, the lifetime values are based on the GMT clock time.
- (Optional) Configure the tolerance value for the keys.Note: Because of the potential for key overlap when the duration between the first key end-time and the following key start-time is short, RUCKUS recommends that you configure a minimum tolerance of 180 seconds to maintain hitless key rollover.The following example configures a 200 second tolerance period for the keychain profile "mka-sample-key-100."
The following example creates the MKA
keychain "sample" and configures the underlying options. The configured options are
confirmed in the output of the show keychain name command.
device# configure terminal
device(config)# keychain sample mka
device(config-keychain-mka-sample)# key-id 100
device(config-keychain-mka-sample-key-100)# authentication-algorithm aes-128-cmac
device(config-keychain-mka-sample-key-100)# password 12345678123456781234567809abcdef12345678123456781234567809abcdef
device(config-keychain-mka-sample-key-100)# send-lifetime start 02-16-2022 04:05:00 end infinite
device(config-keychain-mka-sample-key-100)# tolerance 200
device(config-keychain-mka-sample-key-100)# end
device# show keychain name sample
Keychain: sample
Tolerance: 0
Key-id : 100
AuthAlgorithm: aes-128-cmac
Key-String : *******
Send Lifetime:-
Start : 02-16-2022 04:05:00 End : Infinite
Active : Yes TimeToExpire: Infinite
Timezone : GMT+00