Configure the RSA Keys
As with any VPN configuration, management of RSA keys is not a difficult task, but it can be a complex undertaking. It is important to completely plan your implementation before you begin to configure the peers. To configure and generate your public keys and enter the public keys of your peer, follow these six steps:
|
Step 1 |
Plan the implementation using RSA keys. |
|
Step 2 |
Configure the router host name and domain name. |
|
Step 3 |
Generate the RSA keys. |
|
Step 4 |
Enter your peer RSA public keys. |
|
Step 5 |
Verify the key configuration. |
|
Step 6 |
Manage the RSA keys. |
Each of these steps is discussed in detail in the following sections.
Plan the Implementation Using RSA Keys
Planning a VPN implementation using RSA keys follows the same process as other IPSec configurations; however, you should ensure that you have carefully planned the key generation and exchange. As with any VPN configuration, little margin for error exists when configuring a VPN using RSA keys. It is best to have every portion of the configuration defined before you begin the implementation.
Configure the Router Host Name and Domain Name
An important part of authentication is that the system must be able to correctly identify itself. For this reason, you must configure the host name and domain name of the router. By configuring the host name and domain name on the router prior to generating the RSA keys, you can be sure that the router keys properly identify the router. To configure the host name of the router, use the hostname command while in the global configuration mode. To configure the domain name of the router, use the ip domain-name command with the correct domain name for the router. Example 17-10 shows the commands required to configure the host name and domain name for the router in New York.
Example 17-10 Configuring the Host Name and Domain Name
NewYork#configure terminal NewYork(config)#hostname NewYork NewYork(config)#ip domain-name NewYork.com
Generate the RSA Keys
By default, RSA key pairs do not exist on the Cisco router. You need to add the optional command usage-keys to the command to generate an encryption key pair and an authentication key pair. The command for generating RSA key pairs is crypto key generate rsa usage-keys. This command generates a key pair (one public and one private key). When generating RSA keys, you must select a "modulus length." RSA keys can be generated in four lengths: 360 bit, 512 bit, 1024 bit, and 2048 bit. The longer the modulus length, the more secure the key, and the more time required to generate the key. Cisco recommends a minimum modulus length of 1024 bits. The generation of RSA keys is discussed in greater detail in Chapter 18, "Scaling a VPN Using IPSec with Certificate Authority."
Enter Your Peer RSA Public Keys
After receiving the public key from your peer (in a secure manner), you need to enter the public key into the router. Several commands are required to complete this process:
crypto key pubkey-chain crypto key pubkey-chain rsa addressed-key key-address named-key key-name key-string
Example 17-11 shows the commands required to install the public key from Boston into the peer router in New York.
Example 17-11 Installing the Public Key in the New York Router
|
NewYork(config)# crypto key pubkey-chain rsa |
|||||
|
NewYork |
(config |
pubkey-chain)# addressed-key 192.168.20.1 |
|||
|
NewYork |
(config |
pubkey-key)# key-string |
|||
|
NewYork |
(config |
pubkey)# |
00302017 4A7D385B |
1234EF29 |
335FC973 |
|
NewYork |
(config |
pubkey)# |
2DD50A37 C4F4B0FD |
9DADE748 |
429618D5 |
|
NewYork |
(config |
pubkey)# |
18242BA3 2EDFBDD3 |
4296142A |
DDF7D3D8 |
|
NewYork |
(config |
pubkey)# |
08407685 2F2190A0 |
0B43F1BD |
9A8A26DB |
|
NewYork |
(config |
pubkey)# |
07953829 791FCDE9 |
A98420F0 |
6A82045B |
|
NewYork |
(config |
pubkey)# |
90288A26 DBC64468 |
7789F76E |
EE21 |
|
NewYork |
(config |
pubkey)# |
quit |
||
|
NewYork |
(config |
pubkey-key)# exit |
|||
Verify the Key Configuration
Two commands are used to show the current key configurations on the router. The first command (show crypto key mypubkey rsa) displays the public keys that are installed on the router, and the second (show crypto key pubkey-chain rsa) displays all peer keys installed. Example 17-12 shows the output from the show crypto key pubkey rsa command.
Example 17-12 Viewing RSA Public Keys on the New York Router
|
NewYork# show crypto key mypubkey rsa |
|||
|
% Key pair was generated at: 18:13:49 UTC Mar 23 2003 |
|||
|
Key name: NewYork.newyork.com |
|||
|
Usage: Signature Key |
|||
|
Key Data: |
|||
|
005C300D 06092A86 4886F70D 01010105 00034B00 |
30480241 |
00C5E23B |
55D6AB22 |
|
04AEF1BA A54028A6 9ACC01C5 129D99E4 64CAB820 |
847EDAD9 |
DF0B4E4C |
73A05DD2 |
|
BD62A8A9 FA603DD2 E2A8A6F8 98F76E28 D58AD221 |
B583D7A4 |
71020301 |
0001 |
|
% Key pair was generated at: 18:13:49 UTC Mar 23 2003 |
|||
|
Key name: NewYork.newyork.com |
|||
|
Usage: Encryption Key |
|||
|
Key Data: |
|||
|
00302017 4A7D385B 1234EF29 335FC973 2DD50A37 |
C4F4B0FD |
9DADE748 |
429618D5 |
|
18242BA3 2EDFBDD3 4296142A DDF7D3D8 08407685 |
2F2190A0 |
0B43F1BD |
9A8A26DB |
|
07953829 791FCDE9 A98420F0 6A82045B 90288A26 |
DBC64468 |
7789F76E |
EE21 |
Example 17-13 shows the output from the show crypto key pubkey-chain rsa command.
Example 17-13 Viewing RSA Public Keys on the New York Router
|
NewYork# show crypto key pubkey |
chain rsa |
|
|
Codes: |
M - Manually Configured, |
C - Extracted from certificate |
|
Code |
Usage IP-address |
Name |
|
M |
Signature 192.168.20.1 |
Boston.boston.com |
|
M |
Encryption 192.168.20.1 |
Boston.boston.com |
Manage the RSA Keys
Once generated and installed, the only management of RSA keys that is required is to remove old unused keys. The crypto key zeroize rsa command enables you to remove old keys.
Continue reading here: Configuring the Cisco Router for IPSec VPNs Using CA Support
Was this article helpful?