Explains when cryptographic key pairs require manual generation, how key purpose affects RSA generation, and which generated keys appear in the running configuration.
A FIPS-compliant cryptographic key pair is a collection of key material that
-
uses a key type and size permitted by the documented FIPS mode
-
supports signing, encryption, or both functions, and
-
can be inspected or removed with the corresponding key-management commands.
The router automatically generates cryptographic keys when it boots. Generate keys manually only when required keys are missing.
Key generation in configuration mode
Cisco IOS XR Release 7.3.2 and later supports key-pair generation and deletion in XR configuration mode.
Only keys generated in configuration mode appear in the running configuration.