Product guide

16-7
Key Management System
Configuring Key Chain Management
Note Given transmission delays and the variations in the time value from switch to
switch, it is advisable to include some flexibility in the Accept lifetime of the
keys you configure. Otherwise, the switch may disregard some packets
because either their key has expired while in transport or there are significant
time variations between switches.
To list the result of the commands in figure 16-3:
Figure 16-4. Display of Time-Dependent Keys in the Key Chain Entry
You can use show key-chain to display the key status at the time the command
is issued. Using the information from the example configuration in figures
16-3 and 16-4, if you execute show key-chain at 8:05 on 01/19/03, the display
would appear as follows:
Figure 16-5. Status of Keys in Key Chain Entry “Procurve2”