<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH will not enable on ISR4431 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680356#M25301</link>
    <description>&lt;P&gt;I am working on a&amp;nbsp;ISR4431 that is running&amp;nbsp;Cisco IOS XE Software, Version 16.03.06.&amp;nbsp; For some reason, SSH version 2 will not activate on it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get an error message stating that I need to generate keys greater than 768 bytes for SSH version 2 to work.&amp;nbsp; I have generated keys that are 4096 bytes in length.&amp;nbsp; There are definitely keys in the key store, but for some reason they are not used.&amp;nbsp; Am I not generating the correct type of key?&amp;nbsp; What is the command looking for?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#&amp;nbsp;show crypto key mypubkey all&lt;/P&gt;
&lt;P&gt;% Key pair was generated at: 23:51:41 EST May 11 2018&lt;BR /&gt;Key name: CISCO_IDEVID_SUDI&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; On Cryptographic Device: act2 (label=act2, key index=24)&lt;BR /&gt; Usage: General Purpose Key&lt;BR /&gt; Key is not exportable.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;BR /&gt;% Key pair was generated at: 13:54:26 EST Aug 2 2018&lt;BR /&gt;Key name: XXXXXXXXXXXXXXXXX.XXXX.org&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; Storage Device: not specified&lt;BR /&gt; Usage: Encryption Key&lt;BR /&gt; Key is not exportable. Redundancy enabled.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;BR /&gt;% Key pair was generated at: 13:56:34 EST Aug 2 2018&lt;BR /&gt;Key name: XXXXXXXXXXXXXXXXX.XXXX.org.server&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; Storage Device: not specified&lt;BR /&gt; Usage: Encryption Key&lt;BR /&gt; Key is not exportable. Redundancy enabled.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Aug 2018 20:02:48 GMT</pubDate>
    <dc:creator>zstamm</dc:creator>
    <dc:date>2018-08-02T20:02:48Z</dc:date>
    <item>
      <title>SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680356#M25301</link>
      <description>&lt;P&gt;I am working on a&amp;nbsp;ISR4431 that is running&amp;nbsp;Cisco IOS XE Software, Version 16.03.06.&amp;nbsp; For some reason, SSH version 2 will not activate on it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get an error message stating that I need to generate keys greater than 768 bytes for SSH version 2 to work.&amp;nbsp; I have generated keys that are 4096 bytes in length.&amp;nbsp; There are definitely keys in the key store, but for some reason they are not used.&amp;nbsp; Am I not generating the correct type of key?&amp;nbsp; What is the command looking for?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#&amp;nbsp;show crypto key mypubkey all&lt;/P&gt;
&lt;P&gt;% Key pair was generated at: 23:51:41 EST May 11 2018&lt;BR /&gt;Key name: CISCO_IDEVID_SUDI&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; On Cryptographic Device: act2 (label=act2, key index=24)&lt;BR /&gt; Usage: General Purpose Key&lt;BR /&gt; Key is not exportable.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;BR /&gt;% Key pair was generated at: 13:54:26 EST Aug 2 2018&lt;BR /&gt;Key name: XXXXXXXXXXXXXXXXX.XXXX.org&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; Storage Device: not specified&lt;BR /&gt; Usage: Encryption Key&lt;BR /&gt; Key is not exportable. Redundancy enabled.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;BR /&gt;% Key pair was generated at: 13:56:34 EST Aug 2 2018&lt;BR /&gt;Key name: XXXXXXXXXXXXXXXXX.XXXX.org.server&lt;BR /&gt;Key type: RSA KEYS&lt;BR /&gt; Storage Device: not specified&lt;BR /&gt; Usage: Encryption Key&lt;BR /&gt; Key is not exportable. Redundancy enabled.&lt;BR /&gt; Key Data:&lt;BR /&gt; &amp;lt;REMOVED&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 20:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680356#M25301</guid>
      <dc:creator>zstamm</dc:creator>
      <dc:date>2018-08-02T20:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680363#M25302</link>
      <description>Hi,&lt;BR /&gt;Try "crypto key zeroize rsa" then recreate the key pair.&lt;BR /&gt;&lt;BR /&gt;This works for me:-&lt;BR /&gt;ip ssh version 2&lt;BR /&gt;ip domain-name DOMAIN.NAME&lt;BR /&gt;crypto key generate rsa modulus 2048 &lt;BR /&gt;&lt;BR /&gt;Optional:-&lt;BR /&gt;ip ssh client algorithm encryption aes256-ctr aes192-ctr aes12-ctr&lt;BR /&gt;ip ssh server algorithm encryption aes256-ctr aes192-ctr aes12-ctr&lt;BR /&gt;ip ssh server algorithm mac hmac-sha1&lt;BR /&gt;ip ssh dh min size 2048&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 02 Aug 2018 20:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680363#M25302</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-02T20:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680367#M25304</link>
      <description>&lt;P&gt;I tried zeroizing the RSA keys several times.&amp;nbsp; I get the same error.&amp;nbsp; It acts like the keys are not there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tried the optional configurations that you posted.&amp;nbsp; Does that just change the hash algorithm?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 20:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680367#M25304</guid>
      <dc:creator>zstamm</dc:creator>
      <dc:date>2018-08-02T20:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680376#M25305</link>
      <description>What is the actually error you get? At what point do you get this error, when you input the command or when you attempt to connect?&lt;BR /&gt;&lt;BR /&gt;Yeah, those commands are optional, just defining the algorithms to use.</description>
      <pubDate>Thu, 02 Aug 2018 20:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680376#M25305</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-02T20:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680420#M25306</link>
      <description>&lt;P&gt;cryp key generate rsa general-keys modulus 2048&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 22:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680420#M25306</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-08-02T22:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680619#M25307</link>
      <description>&lt;P&gt;I assume (it's hard to tell with this limited information) that you configured the key with a label, but did not specify that label when configuring SSH. Follow these steps closely and it really should work:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344" target="_blank"&gt;https://community.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 07:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680619#M25307</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-08-03T07:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680799#M25308</link>
      <description>I just noticed that the command "ip ssh rsa keypair-name &amp;lt;SSH-KEY Label&amp;gt;" isn't in most documentation or training materials.  Is this a new step on this firmware or platform?</description>
      <pubDate>Fri, 03 Aug 2018 13:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680799#M25308</guid>
      <dc:creator>zstamm</dc:creator>
      <dc:date>2018-08-03T13:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSH will not enable on ISR4431</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680909#M25311</link>
      <description>&lt;P&gt;This command was introduced in 12.3(4)T,&amp;nbsp;that's really long ago. And yes,&amp;nbsp;it seems that many course designers are not aware of this. Still,&amp;nbsp;I would consider this configuration a best practice.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 15:49:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-will-not-enable-on-isr4431/m-p/3680909#M25311</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2018-08-03T15:49:47Z</dc:date>
    </item>
  </channel>
</rss>

