cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5401
Views
0
Helpful
1
Replies

Removing self signed certificate

ALIAOF_
Level 6
Level 6

Is this a best pratice to leave these on the switch?  I do use ssh to manage the switch but I don't think these are needed for that purpose.  Any security concerns?

crypto pki trustpoint TP-self-signed-xxxxxxxxxxxx

!

crypto pki certificate chain TP-self-signed-xxxxxxxxxxx

1 Accepted Solution

Accepted Solutions

From a security-standpoint, each function that you don't need should be disabled. As you don't need the certificates for SSH you can delete them. If you later decide to use HTTPS then you can add your own enterprise-generated certificate or generate new self-signed certificates.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

View solution in original post

1 Reply 1

From a security-standpoint, each function that you don't need should be disabled. As you don't need the certificates for SSH you can delete them. If you later decide to use HTTPS then you can add your own enterprise-generated certificate or generate new self-signed certificates.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Review Cisco Networking for a $25 gift card