<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Crypto Key RSA no longer supported in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5261318#M1119592</link>
    <description>&lt;P&gt;C9500・C9200Lの17.12.xで同じ問題に直面しました。&lt;BR /&gt;グローバルコンフィギュレーションモードではなく特権モードで実行しなければならないようです。&lt;BR /&gt;&lt;SPAN&gt;17.11.1.aからの&lt;/SPAN&gt;仕様変更の可能性があります。&lt;/P&gt;
&lt;P&gt;BSTの通りにしたら警告は出なくなりました。&lt;BR /&gt;&lt;SPAN&gt;Old Behavior: Router1(config)#crypto key generate rsa label KEYS modulus 2048&lt;BR /&gt;New Behavior: Lab-Router1#crypto key generate rsa label KEYS modulus 2048&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;コンフィギュレーションガイドにこの仕様変更情報が記載されていないことが問題ですね。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1812299"&gt;@thomas-moffat&lt;/a&gt;&amp;nbsp;さんは書きました:&lt;BR /&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have configured a switch on ios 17.12.4 with the following command '&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;key generate rsa general-keys modulus 2048.' Upon entering this command the following was output in the console:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;crypto key generate rsa general-keys modulus 2048' is a hidden command. Use of this command is not recommended/supported and will be removed in future&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Please can someone advise what command is replacing the above, we have roughly 2000 switches all soon to be upgraded to 17.12.4.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwm08390" target="_blank" rel="noopener"&gt;Cisco Bug: CSCwm08390 - Many "Crypto Key" commands trigger a PARSER-5-HIDDEN error when issued in global configuration mode&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9500/software/release/17-12/configuration_guide/sec/b_1712_sec_9500_cg/secure_shell_version_2_support.html#configuration_examples_for_secure_shell_version_2_support" target="_blank"&gt;Security Configuration Guide, Cisco IOS XE Dublin 17.12.x (Catalyst 9500 Switches) - Secure Shell Version 2 Support [Cisco Catalyst 9500 Series Switches] - Cisco&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-12/configuration_guide/sec/b_1712_sec_9300_cg/secure_shell_version_2_support.html#g_how_to_configure_ssh_v2" target="_blank"&gt;Security Configuration Guide, Cisco IOS XE Dublin 17.12.x (Catalyst 9300 Switches) - Secure Shell Version 2 Support [Cisco Catalyst 9300 Series Switches] - Cisco&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2025 10:19:11 GMT</pubDate>
    <dc:creator>Gaming_Bear</dc:creator>
    <dc:date>2025-02-17T10:19:11Z</dc:date>
    <item>
      <title>Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223829#M1117536</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have configured a switch on ios 17.12.4 with the following command '&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;key generate rsa general-keys modulus 2048.' Upon entering this command the following was output in the console:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;crypto key generate rsa general-keys modulus 2048' is a hidden command. Use of this command is not recommended/supported and will be removed in future&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Please can someone advise what command is replacing the above, we have roughly 2000 switches all soon to be upgraded to 17.12.4.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 15:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223829#M1117536</guid>
      <dc:creator>thomas-moffat</dc:creator>
      <dc:date>2024-11-13T15:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223835#M1117537</link>
      <description>&lt;P&gt;the new device support up to 4096 but there is limitation also for this value&lt;/P&gt;
&lt;P&gt;it better to open TAC and ask cisco about this point&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223835#M1117537</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-13T16:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223890#M1117538</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1812299"&gt;@thomas-moffat&lt;/a&gt;&amp;nbsp;Perhaps use Elliptic Curve instead - "crypto key generate ec keysize 256 label EC-KEY"&lt;/P&gt;
&lt;P&gt;"From Cisco IOS XE Release 17.10, the minimum RSA key pair size must be 2048 bits."&lt;/P&gt;
&lt;P&gt;"From Cisco IOS XE Release 17.11, if you want to continue using the weak RSA key, disable CSDL compliance on the device using the&lt;STRONG&gt; &lt;SPAN class="keyword kwd"&gt;crypto&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;engine&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;compliance&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;shield&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;disable&lt;/SPAN&gt; &lt;/STRONG&gt; command, and reboot." &lt;A href="https://www.cisco.com/c/en/us/td/docs/routers/ios/config/17-x/sec-vpn/b-security-vpn/m_sec-secure-shell-v2-0.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/routers/ios/config/17-x/sec-vpn/b-security-vpn/m_sec-secure-shell-v2-0.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 18:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5223890#M1117538</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-11-13T18:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5227272#M1117723</link>
      <description>&lt;P&gt;It seems that modern IOS-XE v17.15.x / v17.x.y &lt;STRONG&gt;gives this error&lt;/STRONG&gt; &lt;U&gt;when you specify&lt;/U&gt; an RSA modulus &lt;U&gt;&lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt;&lt;/U&gt; 1024 bits.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 14:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5227272#M1117723</guid>
      <dc:creator>BrianSekleckiGE</dc:creator>
      <dc:date>2024-11-21T14:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5261318#M1119592</link>
      <description>&lt;P&gt;C9500・C9200Lの17.12.xで同じ問題に直面しました。&lt;BR /&gt;グローバルコンフィギュレーションモードではなく特権モードで実行しなければならないようです。&lt;BR /&gt;&lt;SPAN&gt;17.11.1.aからの&lt;/SPAN&gt;仕様変更の可能性があります。&lt;/P&gt;
&lt;P&gt;BSTの通りにしたら警告は出なくなりました。&lt;BR /&gt;&lt;SPAN&gt;Old Behavior: Router1(config)#crypto key generate rsa label KEYS modulus 2048&lt;BR /&gt;New Behavior: Lab-Router1#crypto key generate rsa label KEYS modulus 2048&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;コンフィギュレーションガイドにこの仕様変更情報が記載されていないことが問題ですね。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1812299"&gt;@thomas-moffat&lt;/a&gt;&amp;nbsp;さんは書きました:&lt;BR /&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have configured a switch on ios 17.12.4 with the following command '&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;key generate rsa general-keys modulus 2048.' Upon entering this command the following was output in the console:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;crypto key generate rsa general-keys modulus 2048' is a hidden command. Use of this command is not recommended/supported and will be removed in future&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Please can someone advise what command is replacing the above, we have roughly 2000 switches all soon to be upgraded to 17.12.4.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwm08390" target="_blank" rel="noopener"&gt;Cisco Bug: CSCwm08390 - Many "Crypto Key" commands trigger a PARSER-5-HIDDEN error when issued in global configuration mode&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9500/software/release/17-12/configuration_guide/sec/b_1712_sec_9500_cg/secure_shell_version_2_support.html#configuration_examples_for_secure_shell_version_2_support" target="_blank"&gt;Security Configuration Guide, Cisco IOS XE Dublin 17.12.x (Catalyst 9500 Switches) - Secure Shell Version 2 Support [Cisco Catalyst 9500 Series Switches] - Cisco&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-12/configuration_guide/sec/b_1712_sec_9300_cg/secure_shell_version_2_support.html#g_how_to_configure_ssh_v2" target="_blank"&gt;Security Configuration Guide, Cisco IOS XE Dublin 17.12.x (Catalyst 9300 Switches) - Secure Shell Version 2 Support [Cisco Catalyst 9300 Series Switches] - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 10:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5261318#M1119592</guid>
      <dc:creator>Gaming_Bear</dc:creator>
      <dc:date>2025-02-17T10:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5278274#M1120462</link>
      <description>&lt;P&gt;To give a conclusive answer as i was dealing with the same issue as well. There is a bug by cisco with the bug id:&amp;nbsp;CSCwm08390&lt;/P&gt;&lt;P&gt;Link:&amp;nbsp;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwm08390" target="_blank" rel="noopener"&gt;https://bst.cisco.com/quickview/bug/CSCwm08390&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Basically it boils down to following sentence:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As of 17.11.1.a, the default command mode for these commands changed from Global configuration (config) to Privileged EXEC (#).&lt;BR /&gt;Old Behavior: Router1(config)#crypto key generate rsa label KEYS modulus 2048&lt;BR /&gt;New Behavior: Router1#crypto key generate rsa label KEYS modulus 2048&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i execute the command outside of the config terminal mode, i dont get a warning message anymore.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 09:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5278274#M1120462</guid>
      <dc:creator>mario.jost</dc:creator>
      <dc:date>2025-04-04T09:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5280710#M1120582</link>
      <description>&lt;P&gt;I've used mod 4096 for decades and am getting this same "hidden/deprecated" notification. &amp;nbsp;With no info about what the new command is to use.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5280710#M1120582</guid>
      <dc:creator>Rob Miller</dc:creator>
      <dc:date>2025-04-11T18:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Crypto Key RSA no longer supported</title>
      <link>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5336905#M1123092</link>
      <description>&lt;P&gt;Thanks for clarifying! Again a message is misleading to weak crypto instead of the command having been moved.&lt;/P&gt;&lt;P&gt;This is the most stupid CLI change unloaded to long standing admins I can imagine. I see my future self adding another conditional into my m4 based configuration templates once this becomes mandatory, and I need to differ between the former and the "new" way.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 13:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-key-rsa-no-longer-supported/m-p/5336905#M1123092</guid>
      <dc:creator>Mathias Peter IT</dc:creator>
      <dc:date>2025-10-08T13:01:51Z</dc:date>
    </item>
  </channel>
</rss>

