Cisco CRS-1 - Carrier Routing System Router Configuration Manual page 162

Ios xr system security configuration guide
Hide thumbs Also See for CRS-1 - Carrier Routing System Router:
Table of Contents

Advertisement

How to Implement Keychain Management
DETAILED STEPS
Command or Action
Step 1
configure
Example:
RP/0/RP0/CPU0:router# configure
Step 2
key chain key-chain-name
Example:
RP/0/RP0/CPU0:router(config)# key chain
isis-keys
RP/0/RP0/CPU0:router(config-isis-keys)#
Step 3
end
or
commit
Example:
RP/0/RP0/CPU0:router(config-isis-keys)# end
or
RP/0/RP0/CPU0:router(config-isis-keys)# commit
Step 4
show key chain key-chain-name
Example:
RP/0/RP0/CPU0:router# show key chain isis-keys
What to Do Next
After completing keychain configuration, see the
section.
Cisco IOS XR System Security Configuration Guide for the Cisco CRS-1 Router
SC-156
Implementing Keychain Management onCisco IOS XR Software
Purpose
Enters global configuration mode.
Creates a name for the keychain.
Note
Configuring only the keychain name without any
key identifiers is considered a nonoperation. When
you exit the configuration, the router does not
prompt you to commit changes until you have
configured the key identifier and at least one of the
global configuration mode attributes or
keychain-key configuration mode attributes (for
example, lifetime or key string).
Saves configuration changes.
When you issue the end command, the system prompts
you to commit changes:
Uncommitted changes found, commit them before
exiting (yes/no/cancel)?
[cancel]:
Entering yes saves configuration changes to the
running configuration file, exits the configuration
session, and returns the router to EXEC mode.
Entering no exits the configuration session and
returns the router to EXEC mode without
committing the configuration changes.
Entering cancel leaves the router in the current
configuration session without exiting or
committing the configuration changes.
Use the commit command to save the configuration
changes to the running configuration file and remain
within the configuration session.
(Optional) Displays the name of the keychain.
Note
The key-chain-name argument is optional. If you do
not specify a name for the key-chain-name
argument, all the keychains are displayed.
Configuring a Tolerance Specification to Accept Keys
OL-20382-01

Advertisement

Table of Contents
loading

Table of Contents