Configure the RSA Keys

As with any VPN configuration, management of RSA keys is not a difficult task, but it can be a complex undertaking. It is important to completely plan your implementation before you begin to configure the peers. To configure and generate your public keys and enter the public keys of your peer, follow these six steps:

Step 1

Plan the implementation using RSA keys.

Step 2

Configure the router host name and domain name.

Step 3

Generate the RSA keys.

Step 4

Enter your peer RSA public keys.

Step 5

Verify the key configuration.

Step 6

Manage the RSA keys.

Each of these steps is discussed in detail in the following sections.

Plan the Implementation Using RSA Keys

Planning a VPN implementation using RSA keys follows the same process as other IPSec configurations; however, you should ensure that you have carefully planned the key generation and exchange. As with any VPN configuration, little margin for error exists when configuring a VPN using RSA keys. It is best to have every portion of the configuration defined before you begin the implementation.

Configure the Router Host Name and Domain Name

An important part of authentication is that the system must be able to correctly identify itself. For this reason, you must configure the host name and domain name of the router. By configuring the host name and domain name on the router prior to generating the RSA keys, you can be sure that the router keys properly identify the router. To configure the host name of the router, use the hostname command while in the global configuration mode. To configure the domain name of the router, use the ip domain-name command with the correct domain name for the router. Example 17-10 shows the commands required to configure the host name and domain name for the router in New York.

Example 17-10 Configuring the Host Name and Domain Name

NewYork#configure terminal NewYork(config)#hostname NewYork NewYork(config)#ip domain-name NewYork.com

Generate the RSA Keys

By default, RSA key pairs do not exist on the Cisco router. You need to add the optional command usage-keys to the command to generate an encryption key pair and an authentication key pair. The command for generating RSA key pairs is crypto key generate rsa usage-keys. This command generates a key pair (one public and one private key). When generating RSA keys, you must select a "modulus length." RSA keys can be generated in four lengths: 360 bit, 512 bit, 1024 bit, and 2048 bit. The longer the modulus length, the more secure the key, and the more time required to generate the key. Cisco recommends a minimum modulus length of 1024 bits. The generation of RSA keys is discussed in greater detail in Chapter 18, "Scaling a VPN Using IPSec with Certificate Authority."

Enter Your Peer RSA Public Keys

After receiving the public key from your peer (in a secure manner), you need to enter the public key into the router. Several commands are required to complete this process:

crypto key pubkey-chain crypto key pubkey-chain rsa addressed-key key-address named-key key-name key-string

Example 17-11 shows the commands required to install the public key from Boston into the peer router in New York.

Example 17-11 Installing the Public Key in the New York Router

NewYork(config)# crypto key pubkey-chain rsa

NewYork

(config

pubkey-chain)# addressed-key 192.168.20.1

NewYork

(config

pubkey-key)# key-string

NewYork

(config

pubkey)#

00302017 4A7D385B

1234EF29

335FC973

NewYork

(config

pubkey)#

2DD50A37 C4F4B0FD

9DADE748

429618D5

NewYork

(config

pubkey)#

18242BA3 2EDFBDD3

4296142A

DDF7D3D8

NewYork

(config

pubkey)#

08407685 2F2190A0

0B43F1BD

9A8A26DB

NewYork

(config

pubkey)#

07953829 791FCDE9

A98420F0

6A82045B

NewYork

(config

pubkey)#

90288A26 DBC64468

7789F76E

EE21

NewYork

(config

pubkey)#

quit

NewYork

(config

pubkey-key)# exit

Verify the Key Configuration

Two commands are used to show the current key configurations on the router. The first command (show crypto key mypubkey rsa) displays the public keys that are installed on the router, and the second (show crypto key pubkey-chain rsa) displays all peer keys installed. Example 17-12 shows the output from the show crypto key pubkey rsa command.

Example 17-12 Viewing RSA Public Keys on the New York Router

NewYork# show crypto key mypubkey rsa

% Key pair was generated at: 18:13:49 UTC Mar 23 2003

Key name: NewYork.newyork.com

Usage: Signature Key

Key Data:

005C300D 06092A86 4886F70D 01010105 00034B00

30480241

00C5E23B

55D6AB22

04AEF1BA A54028A6 9ACC01C5 129D99E4 64CAB820

847EDAD9

DF0B4E4C

73A05DD2

BD62A8A9 FA603DD2 E2A8A6F8 98F76E28 D58AD221

B583D7A4

71020301

0001

% Key pair was generated at: 18:13:49 UTC Mar 23 2003

Key name: NewYork.newyork.com

Usage: Encryption Key

Key Data:

00302017 4A7D385B 1234EF29 335FC973 2DD50A37

C4F4B0FD

9DADE748

429618D5

18242BA3 2EDFBDD3 4296142A DDF7D3D8 08407685

2F2190A0

0B43F1BD

9A8A26DB

07953829 791FCDE9 A98420F0 6A82045B 90288A26

DBC64468

7789F76E

EE21

Example 17-13 shows the output from the show crypto key pubkey-chain rsa command.

Example 17-13 Viewing RSA Public Keys on the New York Router

NewYork# show crypto key pubkey

chain rsa

Codes:

M - Manually Configured,

C - Extracted from certificate

Code

Usage IP-address

Name

M

Signature 192.168.20.1

Boston.boston.com

M

Encryption 192.168.20.1

Boston.boston.com

Manage the RSA Keys

Once generated and installed, the only management of RSA keys that is required is to remove old unused keys. The crypto key zeroize rsa command enables you to remove old keys.

Continue reading here: Configuring the Cisco Router for IPSec VPNs Using CA Support

Was this article helpful?

0 -1