"%Key pair with hostname Company.companyname.com will be invalid"

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
"%Key pair with hostname Company.companyname.com will be invalid" lesniak81 07-21-2008
Posted by lesniak81 on July 21, 2008, 9:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I got this error when I tried to change hostname on PIX 501. I have
discovered that pix uses host name and domain name to generate rsa
key. Is the following enough to sort this problem out?
#ca zeroize rsa
#hostname new_name
#ca gen rsa key 512
#ca save all
What are the consequences? Will that disconnect my vpn users?

Thanks and regards,
lesniak81

Pure Networks
Posted by Walter Roberson on July 21, 2008, 10:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>I got this error when I tried to change hostname on PIX 501. I have
>discovered that pix uses host name and domain name to generate rsa
>key. Is the following enough to sort this problem out?
>#ca zeroize rsa
>#hostname new_name
>#ca gen rsa key 512
>#ca save all

You shouldn't need to zeroize the rsa, but it wouldn't hurt to do so.
The procedure looks fine.

>What are the consequences? Will that disconnect my vpn users?

I believe that eventually, Yes: the next time the key would normally
be negotiated (typically one hour), that due to the RSA key change,
the negotiation would fail, resulting in a disconnect. If you have
host VPN client connections, I don't have a prediction as to what would
happen at that point. For site-to-site connections, as soon as
the remote site had data to send, it would attempt to reconnect,
and that reconnection should work. So my prediction is that site-to-site
connections might experience a brief pause for renegotation, but
would be fine otherwise, but possibly VPN clients might have to
request to reconnect.

Posted by lesniak81 on July 21, 2008, 10:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Jul 21, 3:09=A0pm, rober...@hushmail.com (Walter Roberson) wrote:
> In article <8ce7bb6e-f49b-4650-a98b-5a66aeaf9...@c58g2000hsc.googlegroups=
.com>,
>
> >I got this error when I tried to change hostname on PIX 501. I have
> >discovered that pix uses host name and domain name to generate rsa
> >key. Is the following enough to sort this problem out?
> >#ca zeroize rsa
> >#hostname new_name
> >#ca gen rsa key 512
> >#ca save all
>
> You shouldn't need to zeroize the rsa, but it wouldn't hurt to do so.
> The procedure looks fine.
>
> >What are the consequences? Will that disconnect my vpn users?
>
> I believe that eventually, Yes: the next time the key would normally
> be negotiated (typically one hour), that due to the RSA key change,
> the negotiation would fail, resulting in a disconnect. If you have
> host VPN client connections, I don't have a prediction as to what would
> happen at that point. For site-to-site connections, as soon as
> the remote site had data to send, it would attempt to reconnect,
> and that reconnection should work. So my prediction is that site-to-site
> connections might experience a brief pause for renegotation, but
> would be fine otherwise, but possibly VPN clients might have to
> request to reconnect.

THANKS! :-)

Similar ThreadsPosted
CSS11501 hostname March 23, 2005, 7:26 pm
Vpn tunnel resolve to hostname February 23, 2005, 12:28 pm
PIX 7.0 object-group w/hostname March 31, 2006, 2:37 pm
IPSEC problem with pre-share/hostname January 17, 2007, 1:24 pm
PIX 501 and Connection to Company VPN. July 24, 2005, 9:07 am
voip for my company November 14, 2006, 11:31 am
PIX ISAKMP: invalid udp len July 12, 2005, 9:28 pm
Gigabit over 2 pair? July 4, 2007, 1:58 pm
Trouble using a hostname in the address field for the Radius client in IAS August 11, 2005, 7:59 am
Upgrading a PIX failover pair December 19, 2005, 5:43 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map