HP NonStop SSH Reference Manual
Configuring and Running SSH2
•
79
and the values of parameters INTERVALPENDINGPRIVATEUSERKEY and
INTERVALLIVEPRIVATEUSERKEY.
Default
The default for this parameter is DISABLED resulting in the same behavior as before the introduction of this parameter.
Example
LIFECYCLEPOLICYPRIVATEUSERKEY FIXED
Considerations
•
Users with full SSHCOM access can set or modify KEY attributes LIVE-DATE and EXPIRE-DATE even
when the life-cycle policy for user private keys is set to FIXED.
See also:
INTERVALLIVEPRIVATEUSERKEY , INTERVALPENDINGPRIVATEUSERKEY
LIFECYCLEPOLICYPUBLICUSERKEY
This parameter controls the life-cycle of user public keys. If enabled, a ‘not valid before date’ and a ‘not valid after date’
can be defined for each individual key. This can be achieved by setting the dates explicitly via entity USER
PUBLICKEY attributes LIVE-DATE and EXPIRE-DATE or implicitly via globally defined length of the key pending
time period after key addition and length of the period a key is in ‘LIVE’ state. Only a key in ‘LIVE’ state may be part of
a public key authentication of the user configured with the key.
Parameter Syntax
LIFECYCLEPOLICYPUBLICUSERKEY [
DISABLED
|
FIXED
|
VARIABLE
]
Arguments
DISABLED
Life-cycle control for user public keys will not be enabled. When a public key is added, it is immediately in
state ‘LIVE’ and it will never expire.
FIXED
Users without full SSHCOM access cannot set or alter KEY attributes LIVE-DATE and EXPIRE-DATE. Both
dates will be determined by the CREATION-DATE and the values of parameters
INTERVALPENDINGPUBLICUSERKEY and INTERVALLIVEPUBLICUSERKEY.
VARIABLE
Users with partial access can specify the LIVE-DATE and EXPIRE-DATE when adding a user public key or
when altering the public key. By not specifying these attributes in an ALTER USER PUBLICKEY command,
the values for LIVE-DATE and EXPIRE-DATE will be automatically set depending on the CREATION-DATE
and the values of parameters INTERVALPENDINGPUBLICUSERKEY and
INTERVALLIVEPUBLICUSERKEY.
Default
The default for this parameter is DISABLED resulting in the same behavior as before the introduction of this parameter.
Example
LIFECYCLEPOLICYPUBLICUSERKEY FIXED
Considerations
•
Users with full SSHCOM access can set or modify USER PUBLICKEY attributes LIVE-DATE and EXPIRE-
DATE even when the life-cycle policy for user public keys is set to FIXED.
Summary of Contents for NonStop SSH 544701-014
Page 12: ...xii Contents HP NonStop SSH Reference Manual ...
Page 24: ...24 Preface HP NonStop SSH Reference Manual ...
Page 30: ...30 Introduction HP NonStop SSH Reference Manual ...
Page 46: ...46 Installation Quick Start HP NonStop SSH Reference Manual ...
Page 132: ...132 The SSH User Database HP NonStop SSH Reference Manual ...
Page 214: ...214 SSH and SFTP Client Reference HP NonStop SSH Reference Manual ...
Page 278: ...278 STN Reference HP NonStop SSH Reference Manual ...
Page 298: ...298 Monitoring and Auditing HP NonStop SSH Reference Manual ...
Page 302: ...302 Performance Considerations HP NonStop SSH Reference Manual ...