Any script to let me find out which Cisco switches have RSA key less than 800 bit?
Imagine I have 500 Cisco switches (2950, 3750, 4507), IOS 12.3 but some may have different IOS level.
I know that some of these switches got 'cry key gen rsa' key size = 512.
I need to have key size = 800 bit.
We do not have Cisco Works in place. Someone in my organization tells me that I would need all these switches at 800 bit otherwise CiscoWorks can't login to it. Does that make sense? I am not sure if I understand that correctly.
Question: If it is true that CiscoWorks can't access such switches and let me change that setting automatically, do you know any script which I could use to let me run against a list of IP addresses and query the switches to find out where RSA key is 800 bits? If it is not 800 bit, I would like to log a message so that I could go manually to the switch to re-execute 'cry key gen rsa' and do 800 bit instead.
Re: Any script to let me find out which Cisco switches have RSA
IOS 12.3 doesn't run on any of these switches.
LMS can login to switches with an RSA modulus of 512 bits. It will just use SSHv1 instead of v2. I do not know of any pre-built scripts to change the modulus size; however, it would be relatively trivial to do with expect. You could deploy one command to avoid the interactivity:
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...