11-8
Broadmore 1750 - Release 4.6
Security Management (FIPS Mode)
Key Management
Key Management
A DSA private hosts key is required for SSH2 connection to the Broadmore.
Default DSA Key
During manufacture, a default
host_dsa
key file is placed in the
/SSHD
directory of the
Broadmore CPU. This default key is intended only for use in initializing the Broadmore
after installation at the customer site and should be changed by the SuperUser (Crypto
Officer) before making the Broadmore operational.
NOTE:
The DSA hosts key can only be replaced by the SuperUser while
the Broadmore is in the FIPS mode.
Generating DSA Key Pairs
DSA keys can be generated on a UNIX or Windows host, using key generation utilities
provided as a part of the ssh clients/server software of various vendors.
OpenSSH provides ssh-keygen to generate DSA keys on a UNIX or Windows host.
The ssh-keygen program can be downloaded from the URL
http://www.openssh.org
.
The following example shows how to generate the
host_dsa
key on a UNIX host or on
a Windows PC running Cygwin.
$ ssh-keygen -t dsa -f host_dsa -N "" -C <comments>
Installing the DSA Key
With the Broadmore in FIPS mode, the SuperUser can use an SSH2 client (such as
SecureFX) to log into the Broadmore/SSHield module and install the
host_dsa
key in
the
/SSHD
directory on the Broadmore CPU.
NOTE:
After installing the DSA key, the Broadmore must be rebooted in
order for the change to take effect.
Summary of Contents for Broadmore 1750
Page 1: ...Broadmore TM 1750 USER MANUAL Part Number 770 0020 DC Product Release 4 6 January 2008 ...
Page 24: ...xii Broadmore 1750 Release 4 6 Table of Contents ...
Page 50: ...1 26 Broadmore 1750 Release 4 6 Product Description Alarm Power Module IOM ...
Page 69: ...CHAPTER 3 Receipt of Product In this Chapter Receipt 3 2 Unpacking 3 2 Inspection 3 3 ...
Page 72: ...3 4 Broadmore 1750 Release 4 6 Receipt of Product Damage Reporting ...
Page 82: ...4 10 Broadmore 1750 Release 4 6 Chassis Installation and Grounding AC Power Supply Tray ...
Page 114: ...6 16 Broadmore 1750 Release 4 6 Electrical Installation Software ...
Page 188: ...7 74 Broadmore 1750 Release 4 6 Configuration Help ...
Page 234: ...8 46 Broadmore 1750 Release 4 6 Maintenance and Troubleshooting Summary of Front Panel LEDs ...
Page 244: ...9 10 Broadmore 1750 Release 4 6 Command Line Interface About Command ...
Page 266: ...10 22 Broadmore 1750 Release 4 6 Security Management FTP Login ...
Page 302: ...11 36 Broadmore 1750 Release 4 6 Security Management FIPS Mode sshdShow ...
Page 318: ...11 52 Broadmore 1750 Release 4 6 Security Management FIPS Mode Sanitation Procedures ...
Page 362: ...12 44 Broadmore 1750 Release 4 6 SNMP Configuration Notify Profiles ...
Page 370: ...A 8 Broadmore 1750 Release 4 6 Technical Specifications E3 Unstructured Circuit Emulation SAM ...
Page 373: ...APPENDIX C Software Error Messages In this Appendix Overview System Errors Setup Errors ...
Page 383: ...APPENDIX E Chassis Differences ...
Page 386: ...E 4 Broadmore 1750 Release 4 6 Chassis Differences Software Differences ...
Page 394: ...F 8 Broadmore 1750 Release 4 6 IPv6 Support Deleting a Network Route ...
Page 398: ...G 4 Broadmore 1750 Release 4 6 Broadmore Command List Commands Available at the CLI Prompt ...
Page 408: ...Glossary 10 Broadmore 1750 Release 4 6 Glossary ...