03-19-2019 08:21 AM
Hi all,
Iam about to update a stack of two C3850 switches from a 3.x version to a 16.x version.
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
And are there any other things to keep in mind?
Thanks for any help!
Solved! Go to Solution.
03-19-2019 11:48 PM
@flokki123 wrote:
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
No, I don't think so.
@flokki123 wrote:
And are there any other things to keep in mind?
03-19-2019 11:02 AM
03-19-2019 11:48 PM
@flokki123 wrote:
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
No, I don't think so.
@flokki123 wrote:
And are there any other things to keep in mind?
03-20-2019 04:52 AM
Hey guys,
thanks a lot for your help!
Apparently the new RSA key is only necessary with version 16.3.5.
"When you upgrade to Cisco IOS XE Denali 16.3.5 the SSH access is lost, because it cannot use the CISCO_IDEVID_SUDI_LEGACY RSA server key. Before upgrade, generate the server key using the crypto key generate rsa command in global configuration mode.
To verify whether the RSA server key is available on your device, run the show crypto key command."
BR
02-07-2022 01:54 PM
@Leo Laohoo
"Please note that you're going from 3.X to 16.X. This means there will be a one-off microcode upgrade. Depending on the exact version, this will add 15 minutes (approximately) to the bootup"
I just want to thank you for this update - Upgraded 3850 stack from 3.x to 16.x - faced 15 minutes of additional downtime but no issues with RSA post upgrade. Thank you very much to Cisco Community.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide