Solved

cisco switch 2960 ssh rsa certificate  and ip domain name correction

Posted on 2016-11-23
5
21 Views
Last Modified: 2016-11-29
I had just finished configuring a switch today,  but by mistake i put the domain name incorrect (i.e. ip domain-name 100.test.local).  Then i generated the ssh rsa certificate with this incorrect domain name.  If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
0
Comment
Question by:Shen
  • 3
  • 2
5 Comments
 
LVL 26

Expert Comment

by:Predrag Jovic
ID: 41899718
If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
Yes, it will create problem.
The way to handle it is to change domain name and then zerioze  rsa keys and recreate it again:

(config)# crypto key zeroize rsa
% All RSA keys will be removed.
% All router certs issued using these keys will also be removed.
Do you really want to remove these keys? [yes/no]: y


also it is highly recommended to use label option for your keys - in that case hostname is not used for generation key and hostname can be changed at any moment without need to create new crypto key

(config)#crypto key generate rsa label MYKEY modulus 1100
0
 

Author Comment

by:Shen
ID: 41902656
Thank you very I will try your suggestions this coming Monday and let you know.  By the way why do you use modulus 1100?
0
 
LVL 26

Accepted Solution

by:
Predrag Jovic earned 500 total points
ID: 41902802
By the way why do you use modulus 1100?
Just for example how to do it. :)
I typically use 2048 value.

Modulus Length

When you generate RSA keys, you will be prompted to enter a modulus length. The longer the modulus, the stronger the security. However a longer modules takes longer to generate (see the table below for sample times) and takes longer to use.

Sample Times by Modulus Length to Generate RSA Keys

Router           360 bits                 512 bits           1024 bits               2048 bits (maximum)

Cisco 2500   11 seconds             20 seconds      4 minutes, 38 seconds more than 1 hour

Cisco 4700   less than 1 second   1 second       4 seconds    50 seconds

Cisco IOS software does not support a modulus greater than 4096 bits. A length of less than 512 bits is normally not recommended. In certain situations, the shorter modulus may not function properly with IKE, so we recommend using a minimum modulus of 2048 bits.
Link to article - crypto key generate rsa
0
 

Author Closing Comment

by:Shen
ID: 41904341
It worked. Thanks a lot for your help and suggestions.
0
 
LVL 26

Expert Comment

by:Predrag Jovic
ID: 41906756
You're welcome.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video discusses moving either the default database or any database to a new volume.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now