Solved

cisco switch 2960 ssh rsa certificate  and ip domain name correction

Posted on 2016-11-23
5
67 Views
Last Modified: 2016-11-29
I had just finished configuring a switch today,  but by mistake i put the domain name incorrect (i.e. ip domain-name 100.test.local).  Then i generated the ssh rsa certificate with this incorrect domain name.  If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
0
Comment
Question by:Shen
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 29

Expert Comment

by:Predrag Jovic
ID: 41899718
If i correct the domain name (i.e ip domain-name test.local)  would  this create a problem with the ssh certificate. If so, is there any way to fix this?
Yes, it will create problem.
The way to handle it is to change domain name and then zerioze  rsa keys and recreate it again:

(config)# crypto key zeroize rsa
% All RSA keys will be removed.
% All router certs issued using these keys will also be removed.
Do you really want to remove these keys? [yes/no]: y


also it is highly recommended to use label option for your keys - in that case hostname is not used for generation key and hostname can be changed at any moment without need to create new crypto key

(config)#crypto key generate rsa label MYKEY modulus 1100
0
 

Author Comment

by:Shen
ID: 41902656
Thank you very I will try your suggestions this coming Monday and let you know.  By the way why do you use modulus 1100?
0
 
LVL 29

Accepted Solution

by:
Predrag Jovic earned 500 total points
ID: 41902802
By the way why do you use modulus 1100?
Just for example how to do it. :)
I typically use 2048 value.

Modulus Length

When you generate RSA keys, you will be prompted to enter a modulus length. The longer the modulus, the stronger the security. However a longer modules takes longer to generate (see the table below for sample times) and takes longer to use.

Sample Times by Modulus Length to Generate RSA Keys

Router           360 bits                 512 bits           1024 bits               2048 bits (maximum)

Cisco 2500   11 seconds             20 seconds      4 minutes, 38 seconds more than 1 hour

Cisco 4700   less than 1 second   1 second       4 seconds    50 seconds

Cisco IOS software does not support a modulus greater than 4096 bits. A length of less than 512 bits is normally not recommended. In certain situations, the shorter modulus may not function properly with IKE, so we recommend using a minimum modulus of 2048 bits.
Link to article - crypto key generate rsa
0
 

Author Closing Comment

by:Shen
ID: 41904341
It worked. Thanks a lot for your help and suggestions.
0
 
LVL 29

Expert Comment

by:Predrag Jovic
ID: 41906756
You're welcome.
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA ISP failover 3 31
Factory-Resetting & Configuring Cisco Meraki MR18 Wifi Access Points 3 34
Home internet speed 20 45
802.1x and RDP Issues 6 79
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question