12-12-2019 05:13 AM
Hi all,
Currently we have some issue with ssh connection to some switch, i think rsa keys could be problem. I want to do crypto key zeroize command, but I'm afraid it will also delete crypto pki self signed part:
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl
!
crypto pki trustpoint TP-self-signed-4323392102
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-4323392102
revocation-check none
rsakeypair TP-self-signed-4323392102
!
!
crypto pki certificate chain SLA-TrustPoint
certificate ca 01
30820321 0D06092A D8F256EE 6811D95B ...
I'm not sure if we need this part at all (we don't use ip http server) ?
So my question is if I do crypto key zeroize rsa, is above key going to be deleted and after generating new crypto key is it going to generate this one as well?
Thanks,
Kenny
Solved! Go to Solution.
12-12-2019 06:01 AM
Hello,
I just tested this, zeroizing the RSA key does not touch or affect pki self signed part.
12-12-2019 05:26 AM
@Kenny_M8 Hello
I hope that it can help you.
I
Regards,
Jaderson Pessoa
12-12-2019 06:01 AM
Hello,
I just tested this, zeroizing the RSA key does not touch or affect pki self signed part.
12-13-2019 04:05 AM
Thanks on answers guys.
Like Georg said, it has no affect on pki. Everything is good after deleting and generating new key.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide