You can configure the system master key to enhance data security and reliability.
In an actual network environment, the network and devices are provided and maintained by network providers, and the data belongs to tenants. To provide secure data transmission and storage on the network, ensure that keys are under complete control of the specific user and cannot be obtained by network providers or other tenants. To be specific, users need to have their own key management schemes.
Users can manually modify the system master key based on actual requirements to enhance data security and reliability.
If an error occurs during master key modification, the system prompts a message indicating a master key modification failure and instructs the user to retry it. If the failure persists, contact Huawei technical support personnel.
The system master key can be the default master key or a manually configured master key.
If the default master key is used for a long time, it may be stolen or cracked. The master key that is manually configured needs to be periodically changed and maintained.
To reduce manual maintenance workload, run the set master-key auto-update interval interval-time command to enable automatic update of the master key. The system then periodically generates a new master key that is a string of 32 characters.
To disable the automatic update function, run the undo set master-key auto-update [ interval interval-time ] command. After the automatic update function is disabled, the latest master key of the system is maintained and will not be automatically updated.
Run the display master-key configuration command to check the configuration of the system master key.
In VS mode, this command is supported only by the admin VS.
Run the display master-key version command to display the KMC versions of all boards on a device.
In VS mode, this command is supported only by the admin VS.