TCP Enhanced Authentication
Page 168
7950 SR OS System Management Guide
Default
There are no default entries.
Parameters
entry-id —
Specifies an entry that represents a key configuration to be applied to a keychain.
Values
0 — 63
key —
Specifies a key ID which is used along with
keychain-name
and
direction
to uniquely
identify this particular key entry.
authentication-key —
Specifies the
authentication-key
that will be used by the encryption algorithm.
The key is used to sign and authenticate a protocol packet.
The
authentication-key
can be any combination of letters or numbers. .
Values
A key must be 160 bits for algorithm hmac-sha-1-96 and must be 128 bits for
algorithm aes-128-cmac-96. If the key given with the entry command amounts to
less than this number of bits, then it is padded internally with zero bits up to the
correct length.
algorithm-algorithm —
Specifies an enumerated integer that indicates the encryption algorithm to be
used by the key defined in the keychain.
Values
aes-128-cmac-96 — Specifies an algorithm based on the AES standard
hmac-sha-1-96 — Specifies an algorithm based on SHA-1.
hash-key | hash2-key —
The hash key. The key can be any combination of ASCII characters up to 33
for the
hash-key
and 96 characters for the
hash2-key
in length (encrypted). If spaces are used in
the string, enclose the entire string in quotation marks (“ ”).
This is useful when a user must configure the parameter, but, for security purposes, the actual
unencrypted key value is not provided.
hash —
Specifies the key is entered in an encrypted form. If the
hash
parameter is not used, the key
is assumed to be in a non-encrypted, clear text form. For security, all keys are stored in encrypted
form in the configuration file with the
hash
parameter specified.
hash2 —
Specifies the key is entered in a more complex encrypted form.
begin-time
Syntax
begin-time
[
date] [hours-minutes
] [
UTC
] [
now
] [
forever
]
Context
config>system>security>keychain>direction>bi>entry
config>system>security>keychain>direction>uni>receive>entry
config>system>security>keychain>direction>uni>send>entry
Description
This command specifies the calendar date and time after which the key specified by the keychain
authentication key is used to sign and/or authenticate the protocol stream.
If no date and time is set, the begin-time is represented by a date and time string with all NULLs and
the key is not valid by default.
Parameters
date hours-minutes —
Specifies the date and time for the key to become active.
Values
date: YYYY/MM/DD
hours-minutes: hh:mm[:ss]
Содержание 7950 SR
Страница 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Страница 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Страница 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Страница 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Страница 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Страница 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Страница 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Страница 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Страница 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Страница 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Страница 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Страница 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Страница 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Страница 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Страница 460: ...Standards and Protocols Page 460 Standards and Protocols...