Mailing List Archive

ASR9000 and ssh and "Crypto enginer decrypt failed"
On Sunday May 31 at around 7:34-7:36 (GMT+3) both of our routers
started showing the following error msg:

RP/0/RSP0/CPU0:May 31 07:36:56 : syslog_dev[94]: locald_DSC[328]
PID-217213: ce_pubkey_authenticate: Crypto enginer decrypt failed: No
child processesce_pubkey_authenticate: Crypto enginer decrypt failed:
No child processesce_pubkey_authenticate: Crypto enginer decrypt
failed: No child processesce_pubkey_authenticate: Crypto enginer
decrypt failed: No child processesce_pubkey_authenticate: Crypto
enginer decrypt failed: No child processesce_pubkey_authenticate:
Crypto enginer decrypt failed: No child proces
sesce_pubkey_authenticate: Cryp


At the same time ssh to and from these routers started to become wonky.

I am unable to find this error in Cisco IOS-XR documentation and the
fact that it appeared at the same time in both routers leads me to
suspect that perhaps they were probed by some crafted packet that
caused it so I am wondering whether other IOS-XRs have seen a similar
error message.

Thanks,
Hank

_______________________________________________
cisco-nsp mailing list cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
Re: ASR9000 and ssh and "Crypto enginer decrypt failed" [ In reply to ]
On Wed, 3 Jun 2020 at 14:34, <hank@interall.co.il> wrote:> I am unable
to find this error in Cisco IOS-XR documentation and the
> fact that it appeared at the same time in both routers leads me to
> suspect that perhaps they were probed by some crafted packet that
> caused it so I am wondering whether other IOS-XRs have seen a similar
> error message.

Hi Hank,

If this is accurate, I strongly recommend you to really tighten up
your management plane ACLs (unless you mean it was from an internal
source like your security team?).

Cheers,
James.
_______________________________________________
cisco-nsp mailing list cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/