Key Management System

Configuring Key Chain Management

You can use show key-chainto display the key status at the time the command is issued. Using the information from the example configuration in figures 15-3and 15-4,if you execute show key-chainat 8:05 on 01/19/03, the display would appear as follows:

Figure 15-5. Status of Keys in Key Chain Entry “Procurve2”

The “Procurve1” key chain entry is a time-independent key and will not expire. “Procurve2” uses time-dependent keys, which result in this data:

Expired = 1 Key 1 has expired because its lifetime ended at 8:10 on 01/18/03, the previous day.

Active = 2 Key 2 and 3 are both active for 10 minutes from 8:00 to 8:10 on 1/19/03.

Keys 4 and 5 are either not yet active or expired. The total number of keys is 5.

15-8