03-23-2020 08:22 AM - edited 03-23-2020 08:28 AM
I was thinking of configuring RSA using the label-key syntex so I don't have to configure a domain name. Should you really configure them to be exportable? Basically just trying to understand better the options explained in Cisco Docs with keeping good security in mind.
Solved! Go to Solution.
03-24-2020 11:51 AM
Hi,
Non-exportable means protected in the way that it can't be exported and it can't be found/viualized via any command, or copied over.
Regards,
Cristian Matei.
03-23-2020 10:36 AM
Hi,
The keys should be left as default, non-exportable, unless you have to (from a technical reason) export it, like would be the case of GETVPN COOP, one example that came in my mind now. Otherwise, if you're creating the RSA keys for SSH access for example, you should leave the keys non-exportable and protected by IOS. In the end, the non-export option means non-disclosing the private key.
Regards,
Cristian Matei.
03-23-2020 01:56 PM
03-24-2020 11:51 AM
Hi,
Non-exportable means protected in the way that it can't be exported and it can't be found/viualized via any command, or copied over.
Regards,
Cristian Matei.
03-25-2020 05:33 PM
03-27-2020 05:11 AM
Hi,
One such quick example would be GETVPN COOP.
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide