01-21-2020 04:07 AM
Is it possible to change the cisco switches' public and private key pair?
01-21-2020 04:25 AM
Hello akrmkhls56541,
Recently Cisco announced a problem in the self-sign certificate in devices, and share a workaround to perform change this certificate.
Follow the link
https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html
This document has a 3 workaround to perform the change.
Please rate and mark posts accordingly if you have found any of the information provided useful.
It will hopefully assist others with similar issues in the future.
Best regards,
Lucas Freitas
01-22-2020 12:18 AM
Dear
@lucasfreitas83 wrote:Hello akrmkhls56541,
Recently Cisco announced a problem in the self-sign certificate in devices, and share a workaround to perform change this certificate.
Follow the link
https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html
This document has a 3 workaround to perform the change.
Please rate and mark posts accordingly if you have found any of the information provided useful.
It will hopefully assist others with similar issues in the future.
Best regards,
Lucas Freitas
Dear @lucasfreitas83,
Thanks for your reply, it was useful to a great extent. However, I need to know if I can change the public private key pair of cisco switches or not!
Actually, it is better that I ask my question in the following forms:
1-How many public\private key pairs are there in a cisco switch?
2-What are they used for?
3-Is it possible to replace them with some other values generated externally, for example by puttygen?
4-And also, is it possible to get informed about the key pairs values that already exist in the device?
I'm sorry for my basic questions! I'm totally new in this field!
01-22-2020 03:10 AM
Hello,
no problem, here we all help each other.
1-How many public\private key pairs are there in a cisco switch?
Common is one.
2-What are they used for?
For web access, KPI (VPN)
3-Is it possible to replace them with some other values generated externally, for example by puttygen?
Yes, is possible, in the document that I sent has the procedure.
4-And also, is it possible to get informed about the key pairs values that already exist in the device?
In running config you can see the certificate.
Other document to help you.
Please rate and mark posts accordingly if you have found any of the information provided useful.
It will hopefully assist others with similar issues in the future.
Best regards,
Lucas Freitas
01-22-2020 04:26 AM
Thanks for your reply! I do appreciate it!
Does the device use the same key pair for other tasks, e.g. for symmetric key agreement with other devices or any other activity that needs a public-private key pair?
If I change the certificate, does this impact other activities?
01-22-2020 05:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide