Specifications
© Copyright 2007 Cisco Systems, Inc.
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.
20
PRNG Seed X9.31 This is the seed for X9.31 PRNG. This CSP
is stored in DRAM and updated periodically
after the generation of 400 bytes – after this
it is reseeded with router-derived entropy;
hence, it is zeroized periodically. Also, the
operator can turn off the router to zeroize
this CSP.
DRAM Automatically every 400
bytes, or turn off the router.
PRNG Seed
Key
X9.31 This is the seed key for the PRNG. DRAM Turn off the router
Diffie Hellman
private
exponent
DH The private exponent used in Diffie-Hellman
(DH) exchange as part of IKE. Zeroized
after DH shared secret has been generated.
DRAM Automatically after shared
secret generated.
Diffie Hellman
public key
DH The public key used in Diffie-Hellman (DH)
exchange as part of IKE. Zeroized after the
DH shared secret has been generated.
DRAM Automatically after shared
secret generated.
skeyid Keyed SHA-1 Value derived from the shared secret within
IKE exchange. Zeroized when IKE session
is terminated.
DRAM Automatically after IKE
session terminated.
skeyid_d Keyed SHA-1 The IKE key derivation key for non ISAKMP
security associations.
DRAM Automatically after IKE
session terminated.
skeyid_a HMAC-SHA-1 The ISAKMP security association
authentication key.
DRAM Automatically after IKE
session terminated.
skeyid_e TRIPLE-
DES/AES
The ISAKMP security association
encryption key.
DRAM Automatically after IKE
session terminated.
IKE session
encrypt key
TRIPLE-
DES/AES
The IKE session encrypt key. DRAM Automatically after IKE
session terminated.
IKE session
authentication
key
HMAC-SHA-1 The IKE session authentication key. DRAM Automatically after IKE
session terminated.
ISAKMP
preshared
Shared secret The key used to generate IKE skeyid during
preshared-key authentication. “no crypto
isakmp key” command zeroizes it. This key
can have two forms based on whether the
key is related to the hostname or the IP
address.
NVRAM “# no crypto isakmp key”
IKE hash key HMAC-SHA-1 This key generates the IKE shared secret
keys. This key is zeroized after generating
those keys.
DRAM Automatically after generating
IKE shared secret keys.
IKE RSA
Authentication
private Key
RSA RSA private key for IKE authentication.
Generated or entered like any RSA key, set
as IKE RSA Authentication Key with the
“crypto keyring” or “ca trust-point”
command.
NVRAM “# crypto key zeroize rsa"