cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1140
Views
0
Helpful
2
Replies

Certificate Problem isr1100

murmucka
Level 1
Level 1

Hallo,

since ios upgraded to

17.11 on C1111

router, i continously receive

syslog

error messages:

RSA keypair HTTPS_SS_CERT_KEYPAIR

is in violation of Cisco security compliance guidelines and will be rejected.

How can i delte and re-generate this keypair? I think its hor https server, or? Thank you.

Key name: HTTPS_SS_CERT_KEYPAIR
Key type: RSA KEYS 768 bits
Storage Device: private-config
Usage: General Purpose Key
Key is not exportable. Redundancy enabled.
Key Data: -removed-
1 Accepted Solution

Accepted Solutions

pieterh
VIP
VIP

768 bits key is nowadays considered too weak-> create new RSA-keys suitable for this IOS version
Security Configuration Guide, Cisco IOS XE Dublin 17.11.x (Catalyst 9300 Switches) - Configuring Secure Socket Layer HTTP [Support] - Cisco

crypto key generate rsa

(Optional) Generates an RSA key pair. RSA key pairs are required before you can obtain a certificate for the switch. RSA key pairs are generated automatically. You can use this command to regenerate the keys, if needed.

when new keys are generated you can issue aditional steps
read the document in the link for additional commands to use certificates

View solution in original post

2 Replies 2

pieterh
VIP
VIP

768 bits key is nowadays considered too weak-> create new RSA-keys suitable for this IOS version
Security Configuration Guide, Cisco IOS XE Dublin 17.11.x (Catalyst 9300 Switches) - Configuring Secure Socket Layer HTTP [Support] - Cisco

crypto key generate rsa

(Optional) Generates an RSA key pair. RSA key pairs are required before you can obtain a certificate for the switch. RSA key pairs are generated automatically. You can use this command to regenerate the keys, if needed.

when new keys are generated you can issue aditional steps
read the document in the link for additional commands to use certificates

Key type:

RSA KEYS 768 bits

<<- to weak, change it to 1024 

Review Cisco Networking for a $25 gift card