![HP HP ProCurve Series 6600 Access Security Manual Download Page 395](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101395.webp)
8-33
Configuring Secure Shell (SSH)
SSH Client and Secure Sessions
■
During “public-key” authentication, the client must use its private key to
authenticate itself to the server. There can be only one key pair on the
switch for the manager.
■
The private key should be passphrase protected for highest security; the
user is prompted to enter the passphrase.
■
The private key can be configured by copying it to the SSH client switch
(using the
copy
command).
■
If the public-key authentication fails or the client has not been configured
with a key pair, the “password” method of authentication is used and the
user is prompted for a password.
■
Successful TACACS or RADIUS logins will give the user either operator
or manager privileges. This is important if there are chained SSH sessions.
Copying Client Key Files
Only one ssh client key for authenticating the manager is allowed on a switch.
The
copy
command allows you to copy the client key files using
sftp, tftp, and
usb or xmodem
, allowing encryption and authentication through SSH. There is
no way to generate the private key on the switch; it must be copied onto the
switch.
To load the client’s private key onto the switch, use one of these commands.
Syntax
:
copy sftp ssh-client-key [user <username> | <username@>] <hostname
| IPv4 | IPv6>
<private-key-filename
> [port <
tcp-port-num
>]
copy tftp ssh-client-key< hostname | IPv4 | IPv6> <
private-key-filename
>
copy usb ssh-client-key <
private-key-filename
>
copy xmodem ssh-client-key
Copies the client key file <
private-key-filename
> onto the
switch.
ssh-client-key:
The client key file being copied to the
switch. The file must contain an RSA or DSA key.
[user <username | username@>]:
Optional; there must be
configured usernames for Operator and Manager.
If no
username
is specified, the client’s current
username
is used. There will be a prompt for a password if needed.
hostname:
Specifies the hostname of the SFTP or TFTP
server.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......