Configuring Secure Shell (SSH)
Terminology
N o t e
SSH in ProCurve switches is based on the OpenSSH software toolkit. For more
information on OpenSSH, visit
http://www.openssh.com
.
Switch SSH and User Password Authentication .
This option is a subset
of the client public-key authentication shown in figure 7-1. It occurs if the
switch has SSH enabled but does not have login access (
login public-key
)
configured to authenticate the client’s key. As in figure 7-1, the switch authen
ticates itself to SSH clients. Users on SSH clients then authenticate themselves
to the switch (login and/or enable levels) by providing passwords stored
locally on the switch or on a or RADIUS server. However, the client
does not use a key to authenticate itself to the switch.
ProCurve
Switch
(SSH
Server)
SSH
Client
Work-
Station
1. Switch-to-Client SSH
2. User-to-Switch (login password and
enable password authentication)
options:
– Local
–
Figure 7-2. Switch/User Authentication
On the switches covered in this guide, SSH supports these data encryption
methods:
■
3DES (168-bit)
■
DES (56-bit)
N o t e
ProCurve switches use RSA keys for internally generated keys (v1/v2 shared
host key & v1 server key). The switch supports both RSA and DSA/DSS keys
for clients. All references to either a public or private key mean keys generated
using these algorithms, unless otherwise noted
Terminology
■
SSH Server:
An ProCurve switch with SSH enabled.
■
Key Pair:
A pair of keys generated by the switch or an SSH client
application. Each pair includes a public key, that can be read by
anyone and a private key held internally in the switch or by a client.
7-3
Summary of Contents for J8697A
Page 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Page 2: ......
Page 22: ...Product Documentation Feature Index xx ...
Page 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Page 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Page 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Page 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Page 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Page 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Page 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Page 388: ...10 Index ...
Page 389: ......