314
Configuring first-time authentication support
When the router connects to the SSH server as an SSH client, configure whether the router supports first-
time authentication.
•
With first-time authentication, when an SSH client not configured with the server host public key
accesses the server for the first time, the user can continue accessing the server and save the host
public key on the client. When accessing the server again, the client uses the saved server host
public key to authenticate the server.
•
Without first-time authentication, a client not configured with the server host public key refuses to
access the server. To enable the client to access the server, you must configure the server host
public key and specify the public key name for authentication on the client in advance.
Enable the router to support first-time authentication
To do...
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable the router to support
first-time authentication.
ssh client first-time enable
Optional.
By default, first-time authentication
is supported on a client.
Disable first-time authentication
For successful authentication of an SSH client not supporting first-time authentication, the server host
public key must be configured on the client, and the public key name must be specified.
To disable first-time authentication:
To do...
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Disable first-time
authentication support.
undo ssh client first-time
Required.
By default, first-time authentication
is supported on a client.
3.
Configure the server host
public key.
."
Required.
The method for configuring the
server host public key on the client
is similar to that for configuring
client public key on the server.
4.
Specify the host public key
name of the server.
ssh client
authentication server
server
assign publickey
keyname
Required.