Solved

cisco switch 2960 ssh rsa certificate  and ip domain name correction

Posted on 2016-11-23
5
60 Views
Last Modified: 2016-11-29
I had just finished configuring a switch today,  but by mistake i put the domain name incorrect (i.e. ip domain-name 100.test.local).  Then i generated the ssh rsa certificate with this incorrect domain name.  If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
0
Comment
Question by:Shen
  • 3
  • 2
5 Comments
 
LVL 28

Expert Comment

by:Predrag Jovic
ID: 41899718
If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
Yes, it will create problem.
The way to handle it is to change domain name and then zerioze  rsa keys and recreate it again:

(config)# crypto key zeroize rsa
% All RSA keys will be removed.
% All router certs issued using these keys will also be removed.
Do you really want to remove these keys? [yes/no]: y


also it is highly recommended to use label option for your keys - in that case hostname is not used for generation key and hostname can be changed at any moment without need to create new crypto key

(config)#crypto key generate rsa label MYKEY modulus 1100
0
 

Author Comment

by:Shen
ID: 41902656
Thank you very I will try your suggestions this coming Monday and let you know.  By the way why do you use modulus 1100?
0
 
LVL 28

Accepted Solution

by:
Predrag Jovic earned 500 total points
ID: 41902802
By the way why do you use modulus 1100?
Just for example how to do it. :)
I typically use 2048 value.

Modulus Length

When you generate RSA keys, you will be prompted to enter a modulus length. The longer the modulus, the stronger the security. However a longer modules takes longer to generate (see the table below for sample times) and takes longer to use.

Sample Times by Modulus Length to Generate RSA Keys

Router           360 bits                 512 bits           1024 bits               2048 bits (maximum)

Cisco 2500   11 seconds             20 seconds      4 minutes, 38 seconds more than 1 hour

Cisco 4700   less than 1 second   1 second       4 seconds    50 seconds

Cisco IOS software does not support a modulus greater than 4096 bits. A length of less than 512 bits is normally not recommended. In certain situations, the shorter modulus may not function properly with IKE, so we recommend using a minimum modulus of 2048 bits.
Link to article - crypto key generate rsa
0
 

Author Closing Comment

by:Shen
ID: 41904341
It worked. Thanks a lot for your help and suggestions.
0
 
LVL 28

Expert Comment

by:Predrag Jovic
ID: 41906756
You're welcome.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

827 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question