Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

When trying to generate the general purpose Secure Shell (SSH) keys on the 3725 router, the user receive the %CRYPTO-3-RSA_SELFTEST_FAILED: Generated RSA key failed self test error message

Core issue

This error is most commonly seen on a router that has the AIM-VPN/EPII with Device ID 00, and it running the Cisco IOS  version 12.3.13 with IP/FW/IDS PLUS IPSEC 3DES feature set.

This issue is documented in Cisco bug ID CSCse42201.

You can check the product name and the device ID of the AIM module by issuing the show crypto engine configuration.


For a workaround, perform these steps:

  1. Disable the HW encryption module by issuing the no crypto engine accelerator command.

  2. Generate the RSA keys by issuing the crypto key generate rsa general-keys modulus 1024 command.

  3. Enable the HW encryption module by issuing the crypto engine accelerator configuration command.

  4. Upgrade the Cisco IOS  version if running 12.3.13 (12.3.13 is a deferred release).

  5. Replace the AIM module so that the device ID is not 00.
Version history
Revision #:
1 of 1
Last update:
‎06-22-2009 04:09 PM
Updated by:
Labels (1)