23
Catalyst 6509 Switch, Cisco 7606 Router, and Cisco 7609 Router with VPN Services Module Certification Note
OL-6334-01
Cryptographic Key Management
Table 4
lists the services accessing the CSPs, the type of access and which role accesses the CSPs.
22
authentication key
This key is used by the router to authenticate itself to the
peer. The router or switch gets the password (that is used
as this key) from the AAA server and sends it onto the
peer. The password retrieved from the AAA server is
zeroized upon completion of the authentication attempt.
DRAM
(plaintext)
23
ssh server key
The RSA public key used in SSH. It is zeroized after the
termination of the SSH session. This key does not need to
be zeroized because it is a public key.
DRAM
(plaintext)
24
PPP authentication
key
The authentication key used in PPP. This key is in the
DRAM and not zeroized at runtime. To zeroize the key,
you can turn off the switch or the router.
DRAM
(plaintext)
25
authentication key2 This key is used by the router to authenticate itself to the
peer. The key is identical to key 22 except that it is
retrieved from the local database (on the switch or
router). Issuing the command
no username password
zeroizes the password (that is used as this key) from the
local database.
NVRAM
(plaintext)
26
ssh encryption key
This is the SSH session key. It is zeroized when the SSH
session is terminated.
DRAM
(plaintext)
27
User Password
The password of the user role. This password is zeroized
by overwriting it with a new password.
NVRAM
(plaintext)
28
CO Enable
Password
The plaintext password of the cryptographic officer (CO)
role. This password is zeroized by overwriting it with a
new password.
NVRAM
(plaintext)
29
CO Enable Secret
Password
The ciphertext password of the cryptographic officer
(CO) role. The algorithm used to encrypt this password is
not FIPS approved; this password is considered plaintext
for FIPS purposes. This password is zeroized by
overwriting it with a new password.
NVRAM
(plaintext)
30
Radius shared
secret
The RADIUS shared secret. This shared secret is
zeroized by executing the
no
form of the RADIUS
shared-secret set command.
NVRAM
(plaintext)
DRAM
(plaintext)
31
shared
secret
The shared secret. This shared secret is
zeroized by executing the
no
form of the
shared-secret set command.
NVRAM
(plaintext)
DRAM
(plaintext)
Table 3
Critical Security Parameters (continued)
CSP
Number
Key or CSP Name
Description
Storage