?
Solved

cisco switch 2960 ssh rsa certificate  and ip domain name correction

Posted on 2016-11-23
5
Medium Priority
?
100 Views
Last Modified: 2016-11-29
I had just finished configuring a switch today,  but by mistake i put the domain name incorrect (i.e. ip domain-name 100.test.local).  Then i generated the ssh rsa certificate with this incorrect domain name.  If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
0
Comment
Question by:Shen
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 30

Expert Comment

by:Predrag
ID: 41899718
If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
Yes, it will create problem.
The way to handle it is to change domain name and then zerioze  rsa keys and recreate it again:

(config)# crypto key zeroize rsa
% All RSA keys will be removed.
% All router certs issued using these keys will also be removed.
Do you really want to remove these keys? [yes/no]: y


also it is highly recommended to use label option for your keys - in that case hostname is not used for generation key and hostname can be changed at any moment without need to create new crypto key

(config)#crypto key generate rsa label MYKEY modulus 1100
0
 

Author Comment

by:Shen
ID: 41902656
Thank you very I will try your suggestions this coming Monday and let you know.  By the way why do you use modulus 1100?
0
 
LVL 30

Accepted Solution

by:
Predrag earned 2000 total points
ID: 41902802
By the way why do you use modulus 1100?
Just for example how to do it. :)
I typically use 2048 value.

Modulus Length

When you generate RSA keys, you will be prompted to enter a modulus length. The longer the modulus, the stronger the security. However a longer modules takes longer to generate (see the table below for sample times) and takes longer to use.

Sample Times by Modulus Length to Generate RSA Keys

Router           360 bits                 512 bits           1024 bits               2048 bits (maximum)

Cisco 2500   11 seconds             20 seconds      4 minutes, 38 seconds more than 1 hour

Cisco 4700   less than 1 second   1 second       4 seconds    50 seconds

Cisco IOS software does not support a modulus greater than 4096 bits. A length of less than 512 bits is normally not recommended. In certain situations, the shorter modulus may not function properly with IKE, so we recommend using a minimum modulus of 2048 bits.
Link to article - crypto key generate rsa
0
 

Author Closing Comment

by:Shen
ID: 41904341
It worked. Thanks a lot for your help and suggestions.
0
 
LVL 30

Expert Comment

by:Predrag
ID: 41906756
You're welcome.
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question