Chapter 16: Radio Configuration (CLI)
Configuring AES-256 Payload Encryption (CLI)
phn-3963_004v000
Page 16-259
When you press <Enter>, the following prompt appears:
Please enter key:
Enter the master key and press <Enter>. The master key must be between 8 and 32 ASCII
characters. The characters
do not
appear as you type them. To display the master key and verify
that you typed it correctly, enter the
payload encryption status show
command described
above. You can copy the master key from the output of this command.
To generate the master key automatically, enter the following command in Traffic Encryption view:
Traffic Encryption [2/x]> master key generate
A random master key is generated. You must copy and paste this key to the remote end of the link
to ensure that both sides of the link have the same master key. To display and copy the master
key, enter the
traffic encryption status show
command described above. You can copy the
master key from the output of this command.
You can set all master keys defined on the unit to zero value. To zeroize the master keys, enter the
following command in root view:
root> payload encryption key zeroize
Warning
Executing this command formats the unit’s disk, and renders the unit non-operational.
If it is necessary to use this command, contact Cambium Networks Technical Support
for instructions how to re-configure the unit.
The session key is automatically regenerated at defined intervals. To set the session key
regeneration interval, enter the following command in Traffic Encryption view:
Traffic Encryption [x/x]> payload encryption session-key period set
<00:00-00:00>
Enter the regeneration interval in hours and minutes (HH:MM). For example, the following
command configures radio interface 1 to regenerate the session key every 4 hours and 15 minutes:
Traffic Encryption [2/1]> payload encryption session-key period set 04:15
To display the session key regeneration interval, enter the following command in Traffic
Encryption view:
Traffic Encryption [2/x]> payload encryption session-key period show
Note
Any time payload encryption fails, the Operational status of the link is Down until
payload encryption is successfully restored.