- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2019 08:21 AM
Hi all,
Iam about to update a stack of two C3850 switches from a 3.x version to a 16.x version.
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
And are there any other things to keep in mind?
Thanks for any help!
Solved! Go to Solution.
- Labels:
-
Other Network
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2019 11:48 PM
@flokki123 wrote:
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
No, I don't think so.
@flokki123 wrote:
And are there any other things to keep in mind?
- Read: Upgrading from Cisco IOS XE Denali 16.1.1 to 16.1.x, 16.2.x, or 16.3.x in Install Mode
- Please note that you're going from 3.X to 16.X. This means there will be a one-off microcode upgrade. Depending on the exact version, this will add 15 minutes (approximately) to the bootup.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2019 11:02 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2019 11:48 PM
@flokki123 wrote:
Somewhere I read that you have to generate a new RSA key before the update. Is that correct?
No, I don't think so.
@flokki123 wrote:
And are there any other things to keep in mind?
- Read: Upgrading from Cisco IOS XE Denali 16.1.1 to 16.1.x, 16.2.x, or 16.3.x in Install Mode
- Please note that you're going from 3.X to 16.X. This means there will be a one-off microcode upgrade. Depending on the exact version, this will add 15 minutes (approximately) to the bootup.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2019 04:52 AM
Hey guys,
thanks a lot for your help!
Apparently the new RSA key is only necessary with version 16.3.5.
"When you upgrade to Cisco IOS XE Denali 16.3.5 the SSH access is lost, because it cannot use the CISCO_IDEVID_SUDI_LEGACY RSA server key. Before upgrade, generate the server key using the crypto key generate rsa command in global configuration mode.
To verify whether the RSA server key is available on your device, run the show crypto key command."
BR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2022 01:54 PM
@Leo Laohoo
"Please note that you're going from 3.X to 16.X. This means there will be a one-off microcode upgrade. Depending on the exact version, this will add 15 minutes (approximately) to the bootup"
I just want to thank you for this update - Upgraded 3850 stack from 3.x to 16.x - faced 15 minutes of additional downtime but no issues with RSA post upgrade. Thank you very much to Cisco Community.
