Operation Manual – SSH
H3C S5500-EI Series Ethernet Switches
Chapter 1 SSH Configuration
1-8
Caution:
z
Configuration of the
rsa local-key-pair create
and
public-key local create dsa
command can survive a reboot. You only need to configure it once.
z
The length of an RSA server/host key is in the range 512 to 2048 bits. With SSH2,
however, some clients require that the keys generated by the server must not be
less than 768 bits.
z
The length of a DSA host key is in the range 512 to 2048 bits. With SSH2,
nevertheless, some clients require that the keys generated by the server must not
be less than 768 bits.
II. Exporting RSA or DSA key pairs
You can display or export the local RSA or DSA host key for setting the host key on the
remote end.
Follow these steps to display or export an RSA or DSA host key:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Display the local RSA host key on
the screen in a specified format, or
export it to a specified file
public-key local export
rsa
{
openssh
|
ssh1
|
ssh2
} [
filename
]
Display the local DSA host key on
the screen in a specified format, or
export it to a specified file
public-key local export
dsa
{
openssh
|
ssh2
}
[
filename
]
Required
Use either
command.
III. Destroying RSA or DSA key pairs
Follow these steps to destroy an RSA or DSA key pair:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Destroy the local RSA key
pair
public-key local destroy
rsa
Destroy the local DSA key
pair
public-key local destroy
dsa
Required
Use either command.