1-4
To configure the public key of the peer, you can:
z
Configure it manually: You can input on or copy the public key of the peer to the local host.
z
Import it from the public key file: The system automatically converts the public key to a string coded
using the PKCS (Public Key Cryptography Standards). Before importing the public key, you must
upload the peer's public key file (in binary) to the local host through FTP or TFTP.
z
If you choose to input the public key, the public key must be in a correct format. The key data
displayed by the
display public-key local public
command can be used to meet the format
requirements. The public key displayed in other methods may not meet the format requirements,
and the format-incompliant key cannot be saved. Thus, you are recommended to configure the
public key of the peer by importing it from a public key file.
z
The device supports up to 20 host pubic keys of peers.
Follow these steps to configure the public key of a peer manually:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter public key view
public-key peer keyname
—
Enter public key code view
public-key-code begin
—
Configure a public key of the
peer
Type or copy the key
Required
Spaces and carriage returns
are allowed between
characters.
Return to public key view
public-key-code end
—
When you exit public key code
view, the system automatically
saves the public key.
Return to system view
peer-public-key end
—
Follow these steps to import the host public key of a peer from the public key file:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Import the host public key of a
peer from the public key file
public-key peer
keyname
import sshkey
filename
Required
Displaying and Maintaining Public Keys
To do…
Use the command…
Remarks
Display the public keys of the
local key pairs
display public-key local
{
dsa
|
rsa
}
public
Available in any view
Summary of Contents for S7902E
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Page 598: ...ii ...
Page 1757: ...4 9 ...
Page 1770: ...6 4 ...
Page 2017: ...2 11 Figure 2 3 SFTP client interface ...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...