Switches, Hubs, and Modems
cancel
Showing results for 
Search instead for 
Did you mean: 

Can't generate ssh key on 8212zl

Robin Stein
Occasional Visitor

Can't generate ssh key on 8212zl

Firmware K.12.51

Logged in as manager over telnet:
#crypto key generate
Installing new RSA key. If the key/entropy cache is
depleted, this could take up to a minute.
Operation aborted.

#show crypto host-public-key
Host RSA key file corrupt or not found.
Use 'crypto key generate ssh rsa' to create new host key.

Why do I get an "Operation aborted"?

Generating ssl-certs is no problem.
6 REPLIES
Jeff Carrell
Honored Contributor

Re: Can't generate ssh key on 8212zl

i believe on the provision asic switches you are now required to have 'ssh' in the generate command:

'crypto key generate ssh'

on the older switches the keyword 'ssh' was not req'd...

hth...jeff
Jeff Carrell
Honored Contributor

Re: Can't generate ssh key on 8212zl

my bad...you always had to do the full command 'crypto key generate ssh' on old and new platform switches...

i just tried generating a ssh key on a 3500 running 12.47 and it worked just fine...i then zeroized the key...

i just u/l 12.51 to the 3500, rebooted to it and ran the gen again and it worked just fine...

i did the same process above on an 8212zl, same results, worked both times...

so, i don't know why you are getting the 'operation aborted' message...

sorry i couldn't be more help...

cheers...jeff

Robin Stein
Occasional Visitor

Re: Can't generate ssh key on 8212zl

Thanks for checking jeff
Sorry i missed the "ssh" when pasting the command.

I will try it after a reboot.
Robin Stein
Occasional Visitor

Re: Can't generate ssh key on 8212zl

Replacing the SystemSupport Module(SSM)solved the problem.
Robin Stein
Occasional Visitor

Re: Can't generate ssh key on 8212zl

Se above comment.
Matt Hobbs
Honored Contributor

Re: Can't generate ssh key on 8212zl

From memory this issue has been properly solved in K.13.20, there will be a newer version to hit the web soon though. Hardware replacement is not necessary.

As a workaround you can boot to the boot monitor and mkdir /ssh.