Pre-shared key

A peer can support the use of one or more pre-shared keys (PSKs). An instance of MKA operates for each PSK that is administratively configured as active.

A PSK can be created manually using the CLI.

Each PSK is configured with the following fields:

  • CKN

  • CAK value

The CKN must be unique per port among the configured subports and can be used to identify the key in subsequent management operations.

Each static CAK configuration can have two PSK entries for rollover. The active PSK index dictates the CAK that is used for encrypting the MKAPDUs.