cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
754
Views
0
Helpful
7
Replies
Highlighted
Beginner

Change SSH Key on 2960 Switches

Hello,

 

I am trying to change the key for SSH from 1024 to 2048 but I have (so far) no solution for that.

 

Unfortunately, ip ssh rsa keypair-name SSH and crypto key generate rsa general-keys modulus 2048 label SSH don't work.

 

I trying also other combinations...

 

- crypto key generate rsa
- crypto key generate rsa general-keys modulus 2048
- crypto key generate rsa general-keys label SSH modulus 2048

 

None of the above worked...and the SSH key remains 1024.

 

Does anyone know how to change the SSH Key for this switch from 1024 to 2048?

 

Version is Version 12.2(50)SE4.

 

Thank You!

Everyone's tags (2)
1 ACCEPTED SOLUTION

Accepted Solutions
VIP Mentor

Re: Change SSH Key on 2960 Switches

Hello,

 

have you zeroized the existing key first ?

 

crypto key zeroize rsa 

 

?

7 REPLIES 7
VIP Mentor

Re: Change SSH Key on 2960 Switches

Hello,

 

have you zeroized the existing key first ?

 

crypto key zeroize rsa 

 

?

Beginner

Re: Change SSH Key on 2960 Switches

Hello and thanks for your reply.

I didn't try yet.

Is there any risk to lose the connection with the switch ?

VIP Mentor

Re: Change SSH Key on 2960 Switches

If you give a label to the key-pair, you have to assign it to your ssh-config:

https://supportforums.cisco.com/t5/security-documents/guide-to-better-ssh-security/ta-p/3133344

 

Edit: Just see that you did ... Have you first generated the key and then assigned it to the ssh-config?

Beginner

Re: Change SSH Key on 2960 Switches

Hello and thanks for your reply.

 

Yes, I generated the key first.

 

There is no possibly to assign the key (labeled) to the SSH.

 

PTNS03(config)#ip ssh ?
  authentication-retries  Specify number of authentication retries
  dscp                    IP DSCP value for SSH traffic
  logging                 Configure logging for SSH
  precedence              IP Precedence value for SSH traffic
  source-interface        Specify interface for source address in SSH connections
  time-out                Specify SSH time-out interval
  version                 Specify protocol version supported
VIP Mentor

Re: Change SSH Key on 2960 Switches

Hello,

 

do you need more than 1 key ? Unless you do, zeroize everything and create a new key without the label.

 

 

Beginner

Re: Change SSH Key on 2960 Switches

Is there any risk to lose the connection with the switch?
What are the risks if I lose the connection between the zeroize and key generation?
VIP Mentor

Re: Change SSH Key on 2960 Switches

Hello,

 

if this is a remote site, use the 'reload in' command before making any changes. If you lose connectivity, the switch will reload by itself with the working configuration (obviously make sure you save the working config to the startup config first).

CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards