106 Configuring standard security features
Configuring SSH authentication
Incoming authentication is used when the remote host needs to authenticate to the switch. Outgoing
authentication is used when the switch needs to authenticate to a server or remote host and is more
commonly used for the
configUpload
command. Both password and public key authentication can
coexist on the switch.
After the allowed-user is configured, the remaining setup steps must be completed by the allowed-user.
1.
Log in to the switch as the default admin.
2.
Change the allowed-user’s role to admin, if applicable.
switch:admin>
userconfig --change username -r admin
where
username
is the name of the user you want to perform SSH public key authentication, import,
export, and delete keys.
3.
Set up the allowed-user by typing the following command:
switch:admin>
sshutil allowuser username
where
username
is the name of the user you want to perform SSH public key authentication, import,
export, and delete keys.
4.
Generate a key pair for host-to-switch (incoming) authentication by logging in to your host as admin,
verifying that SSH v2 is installed and working (see your host’s documentation as necessary), and
typing the following command:
ssh-keygen -t dsa
If you need to generate a key pair for outgoing authentication, skip steps 4 and 5 and proceed to step
6.
Example: RSA/DSA key pair generation
alloweduser@mymachine:
ssh-keygen -t dsa
Generating public/private dsa key pair.
Enter file in which to save the key (
/users/alloweduser/.ssh/id_dsa
):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /users/alloweduser/.ssh/id_dsa.
Your public key has been saved in /users/alloweduser/.ssh/id_dsa.pub.
The key fingerprint is:
32:9f:ae:b6:7f:7e:56:e4:b5:7a:21:f0:95:42:5c:d1 alloweduser@mymachine
5.
Import the public key to the switch by logging in to the switch as the allowed-user and entering the
following command:
sshUtil importpubkey
Respond to the prompts as follows:
Example: Adding the public key to the switch
IP address
Enter the IP address of the switch. IPv6 is supported by
sshUtil
.
remote directory
Enter the path to the remote directory where the public key is stored.
public key name
Enter the name of the public key.
login name
Enter the name of the user granted access to the host.
password
Enter the password for the host.
Summary of Contents for A7533A - Brocade 4Gb SAN Switch Base
Page 1: ...HP StorageWorks Fabric OS 6 2 administrator guide Part number 5697 0016 Edition May 2009 ...
Page 24: ...24 ...
Page 99: ...Fabric OS 6 2 administrator guide 99 ...
Page 100: ...100 Managing user accounts ...
Page 118: ...116 Configuring standard security features ...
Page 164: ...162 Configuring advanced security features ...
Page 234: ...232 Installing and maintaining firmware ...
Page 268: ...266 Administering advanced zoning ...
Page 284: ...282 Configuring Enterprise class platforms ...
Page 292: ...290 Routing traffic ...
Page 294: ...292 Interoperability for merged SANs ...
Page 302: ...300 Configuring the Distributed Management Server ...
Page 334: ...332 iSCSI gateway service ...
Page 340: ...338 Administering NPIV ...
Page 407: ...Fabric OS 6 2 administrator guide 405 ...
Page 408: ...406 Using the FC FC routing service ...
Page 438: ...434 Administering extended fabrics ...
Page 460: ...456 Administering ISL trunking ...
Page 516: ...512 FICON fabrics ...
Page 526: ...522 Configuring and monitoring FICON Extension Services ...
Page 540: ...536 Configuring the PID format ...
Page 544: ...540 Understanding legacy password behavior ...
Page 546: ...542 Mixed fabric configurations for non merge SANs ...
Page 550: ...546 Migrating from an MP Router to a 400 MP Router ...
Page 558: ...554 Inband Management ...
Page 572: ...568 ...