Cisco uses a built-in cryptographic engine to generate RSA keys directly on the device

When you generate an RSA key pair on a Cisco router, switch, or security appliance, the device uses its own processor and random number generator to create the keys. You do not download or import a pre-made key — Cisco devices build the key material locally using the crypto key generate rsa command, which triggers the device's cryptographic hardware or software module to do the math.

The actual mechanism depends on your device model and IOS version. Older routers use software-based RSA generation. Newer equipment, particularly Cisco ASA firewalls and high-end routers, may offload this work to a dedicated cryptographic processor or hardware security module (HSM) if one is installed. Either way, the process happens on the device itself — not on a Cisco server or external tool.

Key Takeaways

  • Cisco devices generate RSA keys locally using the crypto key generate rsa command, not by downloading them from Cisco or an external source.
  • The device's processor and random number generator create the key pair, with the private key stored in the device's memory or secure storage.
  • You specify the key size (typically 1024, 2048, or 4096 bits) when you run the command, and the device handles the cryptographic computation.
  • Dedicated cryptographic hardware on newer devices may speed up key generation, but the process and result are the same.
  • The generated keys are used for SSH, HTTPS, certificate signing, and other secure communications on the device.

The crypto key generate rsa command and what it does

To generate an RSA key pair on a Cisco device, you enter configuration mode and type crypto key generate rsa. The device then prompts you to choose a key size — usually 512, 1024, 2048, or 4096 bits. Larger keys take longer to generate but are more secure. A 2048-bit key is standard for most modern deployments.

Once you confirm the key size, the device's processor begins the RSA algorithm: it generates two large random prime numbers, multiplies them together, and performs the mathematical operations needed to create a public key and a private key. This can take anywhere from a few seconds (for 1024-bit keys on modern hardware) to several minutes (for 4096-bit keys on older routers). During generation, you may see a progress indicator or be asked to move the mouse or type random characters to seed the random number generator — this adds entropy to make the keys less predictable.

When the process finishes, the device stores the private key in its local storage (usually NVRAM or flash memory) and keeps the public key in memory. The private key never leaves the device unless you explicitly export it, which is rare and requires additional commands.

Where the randomness comes from

RSA key generation depends on high-quality random numbers. Cisco devices use a combination of sources: the device's internal random number generator (RNG), timing data from network packets, and sometimes user input (like keyboard activity) to seed the process. The goal is to make the two prime numbers truly unpredictable so that an attacker cannot guess or recreate the key.

On devices with a dedicated cryptographic processor or HSM, the random number generation may be handled by that hardware module, which often has its own entropy source. This is considered more secure than software-only RNG because hardware-based entropy is harder to predict or manipulate.

If you are generating keys on a device with very little network traffic or user activity, the RNG may take longer to gather enough entropy. This is why the generation process sometimes pauses or asks you to provide additional input — the device is waiting for enough random data to create a strong key.

How key size affects generation time and security

The key size you choose determines both how long generation takes and how secure the resulting key is. A 512-bit key generates almost instantly but is considered weak by modern standards and should not be used for new deployments. A 1024-bit key takes a few seconds and was once standard but is now considered marginal. A 2048-bit key takes 10 to 60 seconds on most devices and is the current industry standard. A 4096-bit key can take several minutes but provides stronger security for long-term use.

The relationship is not linear — doubling the key size does not double the generation time. RSA key generation is computationally expensive, and larger keys require significantly more processing. On a router with a slow processor, generating a 4096-bit key might take 10 minutes or more. On a modern ASA with a dedicated crypto engine, the same operation might take 2 to 3 minutes.

For most Cisco deployments, 2048-bit keys are sufficient and strike a balance between security and performance. If you are securing highly sensitive traffic or need the key to remain secure for decades, 4096-bit keys are worth the wait.

Where the generated keys are stored

After generation, Cisco devices store the private key in a secure location on the device itself. On routers, this is typically NVRAM (non-volatile RAM) or flash memory. On ASA firewalls, the key is stored in the device's secure storage, often encrypted with a master key. The public key is also stored locally and is included in any certificate the device generates or in SSH host key exchanges.

The private key is protected by the device's access control — only users with administrative privileges can view or export it. If you back up the device's configuration, the private key is included in that backup, so you should treat backups as sensitive files and store them securely.

If the device is rebooted or the configuration is erased, the keys are lost unless you have a backup. This is why many organizations keep a copy of their Cisco device keys in a secure location or use a hardware security module (HSM) to store keys separately from the device.

Using the generated keys for SSH, HTTPS, and certificates

Once you have generated an RSA key pair, Cisco devices use it for several purposes. The most common are SSH (Secure Shell) for remote management and HTTPS for web-based management interfaces. When you enable SSH on a router, it automatically uses the RSA key pair you generated to authenticate the device and encrypt the connection.

You can also use the RSA key pair to generate a self-signed certificate, which is useful for HTTPS and for signing other certificates. A self-signed certificate is one that the device signs with its own private key — no external certificate authority is involved. This certificate is then presented to anyone connecting to the device via HTTPS or other secure protocols.

For more formal deployments, you can use the RSA key pair to generate a certificate signing request (CSR), which you send to a certificate authority (CA) like Verisign or your organization's internal CA. The CA signs the request with its own key, creating a certificate that is trusted by external systems because the CA is trusted.

Regenerating keys and managing multiple key pairs

If you suspect a key has been compromised or if you are upgrading security standards, you can generate a new RSA key pair using the same crypto key generate rsa command. The device will prompt you to confirm that you want to replace the existing key. Once you confirm, the old key is overwritten and the new one takes its place.

Some Cisco devices support multiple RSA key pairs with different names or sizes. This is useful if you want to use different keys for different purposes — for example, a 2048-bit key for SSH and a 4096-bit key for certificate signing. You can specify the key name in the command: crypto key generate rsa label keyname. This creates a named key pair that you can reference in other commands.

If you are managing many Cisco devices, keeping track of when keys were generated and when they should be rotated is important. Many organizations use a certificate management system or HSM to centralize key management across multiple devices.

Frequently Asked Questions

Can I export an RSA private key from a Cisco device?

Yes, but it requires additional configuration. You can export the private key using the crypto key export command, but the device will encrypt it with a password you provide. Exporting private keys is generally not recommended unless you have a specific reason, such as backing up keys to a secure location or migrating them to another device. Treat exported keys as highly sensitive.

How long does it take to generate a 2048-bit RSA key on a Cisco router?

On most modern routers and ASA firewalls, a 2048-bit key takes 10 to 60 seconds. Older routers with slower processors may take several minutes. The time depends on the device model, processor speed, and current CPU load. If the device is busy processing other tasks, key generation may take longer.

What happens if I generate a new RSA key pair on a device that already has one?

The device will ask you to confirm that you want to replace the existing key. If you confirm, the old key is deleted and the new one takes its place. Any certificates or configurations that relied on the old key will no longer work until you update them with the new key or certificate.

Do I need to generate a new RSA key pair after a software upgrade?

No. RSA keys are stored separately from the operating system and survive software upgrades. However, if you erase the device's configuration or perform a factory reset, the keys will be deleted and you will need to generate new ones.

Can Cisco generate RSA keys on my behalf?

No. Cisco does not generate private keys for customers. Key generation always happens on the device itself, and the private key never leaves the device unless you explicitly export it. This design ensures that only you have access to your private key.