176
To do...
Use the command…
Remarks
2.
Enable the switch to support
first-time authentication.
ssh client first-time enable
Optional.
By default, first-time authentication
is supported on a client.
Disable first-time authentication
For successful authentication of an SSH client not supporting first-time authentication, the server host
public key must be configured on the client, and the public key name must be specified.
To disable first-time authentication:
To do...
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Disable first-time
authentication support.
undo ssh client first-time
Required.
By default, first-time authentication
is supported on a client.
3.
Configure the server host
public key.
."
Required.
The method for configuring the
server host public key on the client
is similar to that for configuring
client public key on the server.
4.
Specify the host public key
name of the server.
ssh client
authentication server
server
assign publickey
keyname
Required.
Establishing a connection between the SSH client and server
To do...
Use the command…
Remarks
Establish a connection
between the SSH
client and the server,
and specify the public
key algorithm,
preferred encryption
algorithm, preferred
HMAC algorithm, and
preferred key
exchange algorithm
For an
IPv4
server
ssh2
server
[
port-number
] [
identity-key
{
dsa
|
rsa
} |
prefer-ctos-cipher
{
3des
|
aes128
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} |
prefer-kex
{
dh-group-
exchange
|
dh-group1
|
dh-group14
} |
prefer-stoc-cipher
{
3des
|
aes128
|
des
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] *
Required.
Use either
command in user
view.
For an
IPv6
server
ssh2
ipv6
server
[
port-number
] [
identity-key
{
dsa
|
rsa
} |
prefer-ctos-cipher
{
3des
|
aes128
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} |
prefer-kex
{
dh-
group-exchange
|
dh-group1
|
dh-group14
} |
prefer-stoc-cipher
{
3des
|
aes128
|
des
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] *