cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
1
Helpful
4
Replies

Switch Domain change, am I required to update/generate a new RSA key?

victoriabardy
Level 4
Level 4

Hello all,

I need to update tacacs on a few nexus 3500 switches and it includes updating the switch domain name.  Does this change require that I generate a new RSA key?  

Please let me know.

Thank you.

 

 

4 Replies 4

@victoriabardy 

 We have similar discussion here in the community.

 Basically, it should not be necessary but as you can see on the link below, the dude had problem in some devices and not in others.

https://community.cisco.com/t5/other-security-subjects/when-changing-ip-domain-name-do-i-regenerate-rsa-keys/td-p/618680

 

Martin L
VIP
VIP

Yes, I would generate new keys; better save then sorry down the road; 

Regards, ML
**Please Rate All Helpful Responses **

It has been my experience that when the domain name changes that a new RSA key is needed. There may be some circumstances where that is not the case, but I agree with ML that the prudent (and safe rather than sorry) thing is to generate new keys.

HTH

Rick

no need new RSA key 

MHM