1-4
z
Import it from the public key file: The system automatically converts the public key to a string coded
using the PKCS (Public Key Cryptography Standards). Before importing the public key, you must
upload the peer's public key file (in binary) to the local host through FTP or TFTP.
z
If you choose to input the public key, the public key must be in a correct format. The key data
displayed by the
display public-key local public
command can be used to meet the format
requirements. The public key displayed in other methods may not meet the format requirements,
and the format-incompliant key cannot be saved. Thus, you are recommended to configure the
public key of the peer by importing it from a public key file.
z
The device supports up to 20 host pubic keys of peers.
Follow these steps to configure the public key of a peer manually:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter public key view
public-key peer keyname
—
Enter public key code view
public-key-code begin
—
Configure a public key of the peer
Type or copy the key
Required
Spaces and carriage returns are
allowed between characters.
Return to public key view
public-key-code end
—
When you exit public key code
view, the system automatically
saves the public key.
Return to system view
peer-public-key end
—
Follow these steps to import the host public key of a peer from the public key file:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Import the host public key of a peer
from the public key file
public-key peer
keyname
import
sshkey
filename
Required
Displaying and Maintaining Public Keys
To do…
Use the command…
Remarks
Display the public keys of the local
key pairs
display public-key local
{
dsa
|
rsa
}
public
Display the public keys of the peers
display public-key peer
[
brief
|
name publickey-name
]
Available in any view