Guest

Preview Tool

Cisco Bug: CSCuq46955 - IOS ISR AM IKEv1 doesnt work with rsa-sig

Last Modified

Sep 27, 2018

Products (74)

  • Cisco IOS
  • Cisco VG204XM Analog Voice Gateway
  • Cisco 886VAG 3G Integrated Services Router
  • Cisco 886VA-CUBE Integrated Services Router
  • Cisco 2951 Integrated Services Router
  • Cisco 1905 Serial Integrated Services Router
  • Cisco 819 Hardened Integrated Services Router
  • Cisco C892FSP Integrated Services Router
  • Cisco 892W Integrated Services Router
  • Cisco 881SRSTW Integrated Services Router
View all products in Bug Search Tool Login Required

Known Affected Releases

15.3(3)M

Description (partial)

Symptom:
versions: 15.1 - 15.3.M3:
while at least one ISKMP policy is configured for pre shared key:

crypto isakmp policy 15
 authentication pre-share

ISAKMP 1st phase cannot be completed with error:

*Aug 20 08:32:38.632: ISAKMP:(0): unable to compute hash!
*Aug 20 08:32:38.632: ISAKMP:(0): unable to compute hash for signature!

Version:15.4.3:
ISAKMP workaround doesn't work with the error on the initiator:

Aug 20 08:46:03.861: %CRYPTO-3-IKMP_QUERY_KEY: Querying key pair failed. 
Aug 20 08:46:03.861:  ISAKMP (1001): process_rsa_sig: Querying key pair failed.

Conditions:
Aggressive Mode with PKI and at least one ISKMP policy is configured for pre shared key:
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.