cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
921
Views
0
Helpful
4
Replies

Router Crypto key

jack samuel
Level 1
Level 1

Dears

I am replacing the old router which is configured with GET VPN & DMVPN, and I can see the below commands in the old router, I just want to know what these commands are doing in the router,

crypto pki server ROUTER-CA
 database level complete
 database archive pem password 7 123123123123123
 issuer-name cn=sslvpn.banksohar.net,ou=secops,o=BANKSOHAR
 grant auto rollover ca-cert
 grant auto
 hash sha512
 eku server-auth client-auth
 shutdown
!
crypto pki trustpoint ROUTER-CA
 revocation-check crl
 rsakeypair ROUTER-CA
!
!
crypto pki certificate chain ROUTER-CA
 certificate ca 01
  30820261 308201CA A0030201 02020101 300D0609 2A864886 F70D0101 05050030
  44311230 10060355 040A1309 42414E4B 534F4841 52310F30 0D060355 040B1306
  7365636F 7073311D 301B0603 55040313 1473736C 76706E2E 62616E6B 736F6861
  722E6E65 74301E17 0D313230 37313230 34353031 365A170D 31353037 31323034
  35303136 5A304431 12301006 0355040A 13094241 4E4B534F 48415231 0F300D06
  0355040B 13067365 636F7073 311D301B 06035504 03131473 736C7670 6E2E6261
  6E6B736F 6861722E 6E657430 819F300D 06092A86 4886F70D 01010105 0003818D
  00308189 02818100 AECE6A8D B7FD525E 69ADCEE6 BF6C6FC4 D970BC51 B75BC6BA
  EC328B92 80429403 E956E1BB 26E4D3F5 CFD28142 725F8D26 A526E025 7D09EA3E
  40C14FCE 66AA6845 09B71D84 F78F6387 8DFB8B9E 61B92686 6E9F2B2D AD3FEB60
  A54A4DB0 D7699A99 FA44CEB9 078A69C4 BBFC4E32 7256D7EF B83033CC F197082A
  EB31A867 DAF294D7 02030100 01A36330 61300F06 03551D13 0101FF04 05300301
  01FF300E 0603551D 0F0101FF 04040302 0186301F 0603551D 23041830 168014CD
  0B8E133A F7C40B44 A406C4FC 700D3DE7 E4C16230 1D060355 1D0E0416 0414CD0B
  8E133AF7 C40B44A4 06C4FC70 0D3DE7E4 C162300D 06092A86 4886F70D 01010505
  00038181 004DE963 BD86D342 78E5E294 B2E03778 8918DBE0 9E160B05 BB9DC296
  F7A2C914 0BF5934A AEDF8BAE 0B216044 DF229329 FD259780 9551B218 400DDC29
  16F7EAA8 5F444F74 41E32413 E6BCE6BC 767F3B7A DA16D017 FC852281 5F792F09
  93516187 137401B2 5D883D6C A27E12AD 1B273581 347427D2 557E216C A317FEE8
  C26BE3A1 8F

crypto key pubkey-chain rsa
 named-key realm-cisco.pub signature
  key-string
   30820122 300D0609 2A864886 F70D0101 01050003 82010F00 3082010A 02820101
   00C19E93 A8AF124A D6CC7A24 5097A975 206BE3A2 06FBA13F 6F12CB5B 4E441F16
   17E630D5 C02AC252 912BE27F 37FDD9C8 11FC7AF7 DCDD81D9 43CDABC3 6007D128
   B199ABCB D34ED0F9 085FADC1 359C189E F30AF10A C0EFB624 7E0764BF 3E53053E
   5B2146A9 D7A5EDE3 0298AF03 DED7A5B8 9479039D 20F30663 9AC64B93 C0112A35
   FE3F0C87 89BCB7BB 994AE74C FA9E481D F65875D6 85EAF974 6D9CC8E3 F0B08B85
   50437722 FFBE85B9 5E4189FF CC189CB9 69C46F9C A84DFBA5 7A0AF99E AD768C36
   006CF498 079F88F8 A3B3FB1F 9FB7B3CB 5539E1D1 9693CCBB 551F78D2 892356AE
   2F56D826 8918EF3C 80CA4F4D 87BFCA3B BFF668E9 689782A5 CF31CB6E B4B094D3
   F3020301 0001
  quit

4 Replies 4

Hi

These crypto keys are used for security certificates, this router could have been configured for VPNs.




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Dear julio,

the same with me.

Dear Julio,

Yes i have a 2 types of vpn  on this GET VPN as a GM connecting to the Key server in HQ and DMVPN only for one site acting as a HUB,

so it this router is acting as a CA ?? or it is pulling information from CA, Please correct me if i m not wrong for DMVPN we don't require a CA server but for GET VPN do we require the router who is a key server to act as a CA ???


thanks

can anybody can help me with the above query

Review Cisco Networking products for a $25 gift card