SERVSELECT™ IP SCPS INSTALLER/USER GUIDE
24
With either of the “or” methods (PW|KEY and KEY|PW), the user access rights are
determined from the authentication method used to authenticate the user.
With either of the “and” methods (PW&KEY and KEY&PW), the user access rights
are determined from the first method specified. If PW&KEY is specified, the access
rights from the password authentication will be used. If KEY&PW is specified, the
access rights from the key authentication will be used.
For more information, see
Using Authentication Modes
in this chapter.
SSH user keys
A user’s SSH key is specified in a User Add or User Set command. You may define a
key even if SSH is not currently enabled. The key can be specified in one of two ways:
•
When using the SSHKEY and FTPIP keyword pair to defi ne the network location
of a user’s SSH key fi le, the SSHKEY parameter specifi es the name of the uuen-
coded (Unix to Unix encoded) public key fi le on an FTP server. The maximum
fi le size that can be received is 4K bytes. The FTPIP parameter specifi es the FTP
server’s IP address. When this method is specifi ed, the SCPS initiates an FTP
client request to the specifi ed IP address. The SCPS then prompts the user for
an FTP username and password for connection. When connected, the SCPS will
GET the specifi ed key fi le and the FTP connection will be closed. The SCPS then
stores the SSH key with the username in the SCPS user database.
•
When using the KEY keyword to specify the SSH key, the KEY parameter
specifi es the actual uuencoded SSH key. This is for confi gurations that do
not implement an FTP server. The SCPS stores the specifi ed key in the
SCPS user database.
The SCPS processes a uuencoded SSH2 public key file with the format described in
the IETF document draft-ietf-secshpublickeyfile-02. The key must follow all format
requirements. The UNIX ssh-keygen2 generates this file format. The SCPS also
processes a uuencoded SSH1 public key file. The UNIX ssh-keygen generates this
file format.
To enable SSH session access to the SCPS:
1.
Issue a Show Server Security command to ensure that you are using an
authentication method other than DS or None.
SHOW SERVER SECURITY
2.
Issue a Server SSH command with the Enable parameter. You may also specify
an authentication method.
SERVER SSH ENABLE AUTH=<
auth
>
Summary of Contents for ServSelect KV119A
Page 1: ...Doc No 590 326 001A...
Page 80: ...NOTES 79...
Page 81: ...NOTES 80...
Page 82: ...NOTES 81...
Page 83: ...NOTES 82...
Page 84: ...Doc No 590 326 001A...