<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Backup &amp; Restore keys in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716590#M537270</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asa1# sh crypto key mypubkey rsa &lt;/P&gt;&lt;P&gt;Key name: blah&lt;/P&gt;&lt;P&gt; Usage: General Purpose Key&lt;/P&gt;&lt;P&gt; Modulus Size (bits): 2048&lt;/P&gt;&lt;P&gt; Key Data:&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;asa1#conf t&lt;/P&gt;&lt;P&gt;asa1(config)# crypto ca export blah identity-certificate&lt;/P&gt;&lt;P&gt;ERROR: The trustpoint does not exist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jun 2011 04:57:28 GMT</pubDate>
    <dc:creator>Gordon Ross</dc:creator>
    <dc:date>2011-06-27T04:57:28Z</dc:date>
    <item>
      <title>Backup &amp; Restore keys</title>
      <link>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716588#M537267</link>
      <description>&lt;P&gt;How do you backup &amp;amp; restore the crypto keys on an ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GTG&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716588#M537267</guid>
      <dc:creator>Gordon Ross</dc:creator>
      <dc:date>2019-03-11T20:50:58Z</dc:date>
    </item>
    <item>
      <title>Backup &amp; Restore keys</title>
      <link>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716589#M537269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the "crypto ca export/import" commands to export and restore crypto keys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c5.html#wp2224326"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c5.html#wp2224326&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c5.html#wp2224488"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c5.html#wp2224488&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jun 2011 22:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716589#M537269</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2011-06-26T22:48:11Z</dc:date>
    </item>
    <item>
      <title>Backup &amp; Restore keys</title>
      <link>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716590#M537270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asa1# sh crypto key mypubkey rsa &lt;/P&gt;&lt;P&gt;Key name: blah&lt;/P&gt;&lt;P&gt; Usage: General Purpose Key&lt;/P&gt;&lt;P&gt; Modulus Size (bits): 2048&lt;/P&gt;&lt;P&gt; Key Data:&lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;asa1#conf t&lt;/P&gt;&lt;P&gt;asa1(config)# crypto ca export blah identity-certificate&lt;/P&gt;&lt;P&gt;ERROR: The trustpoint does not exist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2011 04:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716590#M537270</guid>
      <dc:creator>Gordon Ross</dc:creator>
      <dc:date>2011-06-27T04:57:28Z</dc:date>
    </item>
    <item>
      <title>Backup &amp; Restore keys</title>
      <link>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716591#M537271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I apologize for the confusion, I thought your keys were associated with a trustpoint already.&amp;nbsp; On the ASA, you will not be able to keys directly.&amp;nbsp; You will need to put your rsa key into a trustpoint first.&amp;nbsp; You can then export the certificates + key in a pkcs12 and then extract the key from it using something like openssl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have created a key on my ASA called testkey and have exported it below: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GENERTATING KEY... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#&amp;nbsp; crypto key generate rsa label testkey mod 1024 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAKING DUMMY TRUSTPOINT... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#&amp;nbsp; crypto ca trust dummy &lt;/P&gt;&lt;P&gt;asa(config-ca-trustpoint)# keypair testkey &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EXPORTING KEY... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# crypto ca export dummy pkcs12 cisco123 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: Temporary self-signed certificate is being generated to export the keypair since an associated ID certificate is not available. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2011 17:37:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-restore-keys/m-p/1716591#M537271</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2011-06-27T17:37:54Z</dc:date>
    </item>
  </channel>
</rss>

