1-10
Configuring Whether First-time Authentication is Supported
When the device connects to the SSH server as an SSH client, you can configure whether the device
supports first-time authentication.
z
With first-time authentication, when an SSH client not configured with the server host public key
accesses the server for the first time, the user can continue accessing the server, and save the
host public key on the client. When accessing the server again, the client will use the saved server
host public key to authenticate the server.
z
Without first-time authentication, a client not configured with the server host public key will deny to
access the server. To access the server, a user must configure in advance the server host public
key locally and specify the public key name for authentication.
Enable the device to support first-time authentication
Follow these steps to enable the device to support first-time authentication:
To do...
Use the command…
Remarks
Enter system view
system-view
—
Enable the device to support
first-time authentication
ssh client first-time enable
Optional
By default, first-time authentication is
supported on a client.
Disable first-time authentication
For successful authentication of an SSH client not supporting first-time authentication, the server host
public key must be configured on the client and the public key name must be specified.
Follow these steps to disable first-time authentication:
To do...
Use the command…
Remarks
Enter system view
system-view
—
Disable first-time authentication
support
undo ssh client first-time
Optional
By default, first-time authentication
is supported on a client.
Configure the server public key
Refer to
Configuring a Client Public
Key
Required
The method of configuring server
public key on the client is similar to
that of configuring client public key
on the server.
Specify the host public key name of
the server
ssh client
authentication server
server
assign publickey
keyname
Required
Establishing a Connection Between the SSH Client and the Server
Follow these steps to establish the connection between the SSH client and the server:
To do...
Use the command…
Remarks
Establish a
connection between
the SSH client and
server, and specify
the public key
algorithm, preferred
encryption algorithms,
For an IPv4
server
ssh2
server
[
port-number
] [
identity-key
{
dsa
|
rsa
} |
prefer-ctos-cipher
{
aes128
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
}
|
prefer-kex
{
dh-group-exchange
|
dh-group1
|
dh-group14
} |
prefer-stoc-cipher
{
aes128
|
des
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] *
Required
Use either
command in
user view.