cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
152
Views
0
Helpful
3
Replies

How to add SHA 256 NTP Authentication key.

Zee-Far-Man
Level 1
Level 1

Hello Pros,

we have 5 2960x, ,  with the latest STIG released on last Wednesday.  we need to update the NTP authentication to now use SHA-256.     

The current IOS is running is C2960X-UNIVERSALK9-M 

I was trying to add 

(config)#ntp authentication-key 1 hmac-sha2-256 HEX:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx. The 2960x switch is accepting sha2-256 key.

  1. Does (C2960X-UNIVERSALK9-M) IOS support/accept SHA2-256 key? if not then which IOS version do I have to upgrade with??

 

Thanks, in advanced.

2 Accepted Solutions

Accepted Solutions

vishalbhandari
Spotlight
Spotlight

@Zee-Far-Man 

The Cisco 2960X running the C2960X-UNIVERSALK9-M IOS does not support SHA-256 for NTP authentication. It only supports MD5 for NTP authentication keys. Unfortunately, there's no IOS version for the 2960X that adds support for SHA-256, as this feature is not available on the hardware platform. If SHA-256 is a strict STIG requirement, you may need to consider upgrading to a newer switch model, like the Catalyst 9200 or 9300, which support SHA-256 with the appropriate IOS XE versions

View solution in original post

@vishalbhandari 

That's what I was thinking too.  I tried to add SHA-256 Key to one of 9200 switch and it worked but not on C2960x model.

 

Thank you all Pros for your time and assistance.

 

View solution in original post

3 Replies 3

vishalbhandari
Spotlight
Spotlight

@Zee-Far-Man 

The Cisco 2960X running the C2960X-UNIVERSALK9-M IOS does not support SHA-256 for NTP authentication. It only supports MD5 for NTP authentication keys. Unfortunately, there's no IOS version for the 2960X that adds support for SHA-256, as this feature is not available on the hardware platform. If SHA-256 is a strict STIG requirement, you may need to consider upgrading to a newer switch model, like the Catalyst 9200 or 9300, which support SHA-256 with the appropriate IOS XE versions

@vishalbhandari 

That's what I was thinking too.  I tried to add SHA-256 Key to one of 9200 switch and it worked but not on C2960x model.

 

Thank you all Pros for your time and assistance.