Configuring Secure Shell (SSH)
Further Information on SSH Client Public-Key Authentication
To Create a Client-Public-Key Text File.
These steps describe how to
copy client-public-keys into the switch for challenge-response authentication,
and require an understanding of how to use your SSH client application.
Figure 7-13. Example of a Client Public Key
Bit Size
Exponent <e>
Modulus <n>
Comment
N o t e s
Comments in public key files, such as
in figure 7-13,
may appear in a SSH client application’s generated public key. While such
comments may help to distinguish one key from another, they do not pose any
restriction on the use of a key by multiple clients and/or users.
Public key illustrations such as the key shown in figure 7-13 usually include
line breaks as a method for showing the whole key. However, in practice, line
breaks in a public key will cause errors resulting in authentication failure.
1. Use your SSH client application to create a public/private key pair. Refer
to the documentation provided with your SSH client application for
details. The switch supports the following client-public-key properties:
Property
Supported
Value
Comments
Key Format
ASCII
See figure 7-7 on page 7-13. The key must be one unbroken ASCII string. If you add
more than one client-public-key to a file, terminate each key (except the last one)
with a <CR><LF>. Spaces are allowed within the key to delimit the key’s components.
Note that, unlike the use of the switch’s public key in an SSH client application, the
format of a client-public-key used by the switch does not include the client’s IP
address.
Key Type
RSA or
You can choose either RSA or DSA key types when using the
crypto key generate
DSA
ssh
command. The
cert
and
autorun
parameters only use RSA key types.
Maximum Supported 3072 bits
Shorter key lengths allow faster operation, but also mean diminished security.
Public Key Length
Maximum Host Key
RSA:
Includes the bit size, public index, modulus, any comments, <CR>, <LF>, and all blank
Sizes In Bits
1024, 2048, spaces.
3072
If necessary, you can use an editor application to verify the size of a key. For example,
DSA:
placing a client-public-key into a Word for Windows text file and clicking on
File |
1024
Properties | Statistics
, lets you view the number of characters in the file, including
spaces.
7-25
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......