8-9
Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
1. Assigning a Local Login (Operator) and
Enable (Manager) Password
At a minimum, HP recommends that you always assign at least a Manager
password to the switch. Otherwise, under some circumstances, anyone with
Telnet, web, or serial port access could modify the switch’s configuration.
To Configure Local Passwords.
You can configure both the Operator and
Manager password with one command.
Syntax
:
password < manager | operator | all >
Figure 8-4. Example of Configuring Local Passwords
2. Generating the Switch’s Public and Private Key Pair
You must generate a public and private host key pair on the switch. The switch
uses this key pair, along with a dynamically generated session key pair to
negotiate an encryption method and session with an SSH client trying to
connect to the switch.
The host key pair is stored in the switch’s flash memory, and only the public
key in this pair is readable. The public key should be added to a "known hosts"
file (for example,
$HOME/.ssh/known_hosts
on UNIX systems) on the
copy sftp ssh-client-known-hosts [user <username |
username@>] <hostname | IPv4 | IPv6> <
filename
>
[append]
copy ssh-client-known-hosts sftp [user <username |
username@>] <hostname | IPv4 | IPv6> <
filename
>
copy ssh-server-pub-key sftp [user <username |
username@>] <hostname | IPv4 | IPv6> <
filename
>
crypto key zeroize ssh-client-key
crypto key zeroize ssh-client-known-hosts
show session-list
SSH-Related Commands in This Section
Page
Switch(config)# password all
New password for Operator: ********
Please retype new password for Operator: ********
New password for Manager: *******
Please retype new password for Manager: *******
New pasword for Manager: *******
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......