Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 186
  • Last Modified:

cisco switch 2960 ssh rsa certificate and ip domain name correction

I had just finished configuring a switch today,  but by mistake i put the domain name incorrect (i.e. ip domain-name 100.test.local).  Then i generated the ssh rsa certificate with this incorrect domain name.  If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
0
Shen
Asked:
Shen
  • 3
  • 2
1 Solution
 
Predrag JovicNetwork EngineerCommented:
If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
Yes, it will create problem.
The way to handle it is to change domain name and then zerioze  rsa keys and recreate it again:

(config)# crypto key zeroize rsa
% All RSA keys will be removed.
% All router certs issued using these keys will also be removed.
Do you really want to remove these keys? [yes/no]: y


also it is highly recommended to use label option for your keys - in that case hostname is not used for generation key and hostname can be changed at any moment without need to create new crypto key

(config)#crypto key generate rsa label MYKEY modulus 1100
0
 
ShenAuthor Commented:
Thank you very I will try your suggestions this coming Monday and let you know.  By the way why do you use modulus 1100?
0
 
Predrag JovicNetwork EngineerCommented:
By the way why do you use modulus 1100?
Just for example how to do it. :)
I typically use 2048 value.

Modulus Length

When you generate RSA keys, you will be prompted to enter a modulus length. The longer the modulus, the stronger the security. However a longer modules takes longer to generate (see the table below for sample times) and takes longer to use.

Sample Times by Modulus Length to Generate RSA Keys

Router           360 bits                 512 bits           1024 bits               2048 bits (maximum)

Cisco 2500   11 seconds             20 seconds      4 minutes, 38 seconds more than 1 hour

Cisco 4700   less than 1 second   1 second       4 seconds    50 seconds

Cisco IOS software does not support a modulus greater than 4096 bits. A length of less than 512 bits is normally not recommended. In certain situations, the shorter modulus may not function properly with IKE, so we recommend using a minimum modulus of 2048 bits.
Link to article - crypto key generate rsa
0
 
ShenAuthor Commented:
It worked. Thanks a lot for your help and suggestions.
0
 
Predrag JovicNetwork EngineerCommented:
You're welcome.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now