Key Management System

Configuring Key Chain Management

Adds a key with full time and date

Adds a key with duration expressed in seconds.

Figure 15-3. Adding Time-Dependent Keys to a Key Chain Entry

Note

Given transmission delays and the variations in the time value from switch to

 

switch, it is advisable to include some flexibility in the Accept lifetime of the

 

keys you configure. Otherwise, the switch may disregard some packets

 

because either their key has expired while in transport or there are significant

 

time variations between switches.

 

To list the result of the commands in figure 15-3:

 

 

 

 

 

Figure 15-4. Display of Time-Dependent Keys in the Key Chain Entry

15-7