Administrator Guide

Security Commands 1089
Command Mode
Global Configuration mode
User Guidelines
RSA keys are generated in pairs: one public RSA key and one private RSA key.
These keys are used to encrypt communication with the switch when using
SSH. If your switch already has RSA keys when you issue this command, you
are warned and prompted to replace the existing keys. The keys are not saved
in the switch configuration; they are saved in the file system and the private
key is never displayed to the user. RSA keys, along with other switch
credentials, are distributed to all units in a stack on a configuration save.
Use the crypto key zeroize rsa command to remove RSA key pair from the
system.
Private keys should never be shared with unauthorized users. This command
generates the private public key pairs in the following files:
ssh_host_rsa_key and ssh_host_rsa_key.pub, ssh_host_key and
ssh_host_key.pub files. Both the RSA and DSA keys must be generated to
enable the SSH server.
Example
The following example generates RSA key pairs.
console(config)#crypto key generate rsa
crypto key pubkey-chain ssh
Use the crypto key pubkey-chain ssh command in Global Configuration
mode to enter public key configuration mode in order to manually specify
public keys for SSH clients or an individual user.
Syntax
crypto key pubkey-chain ssh user-key username rsa/dsa
Default Configuration
By default, this command has no public keys configured.