329
public key to decrypt the digital signature received from the server. If the decryption succeeds, the
server passes the authentication.
When you execute any one of the SSH commands on the device to trigger the running of the SSH
application, the SSH server automatically generates two RSA key pairs. You can also use the
public-key local create
command to generate DSA, RSA, or ECDSA key pairs on the device.
Configuration guidelines
When you generate local key pairs, follow these restrictions and guidelines:
•
SSH supports locally generated DSA, RSA, and ECDSA key pairs only with default names.
•
To support SSH clients that use different types of key pairs, generate DSA, RSA, and ECDSA
key pairs on the SSH server.
•
The SSH server operating in FIPS mode supports only RSA and ECDSA key pairs. If both RSA
and ECDSA key pairs exist on the server, the server uses the ECDSA key pair.
•
The
public-key local create rsa
command generates a server key pair and a host key pair for
RSA. In SSH1, the public key in the server key pair is used to encrypt the session key for secure
transmission of the session key. Because SSH2 uses the DH algorithm to generate each
session key on the SSH server and the client, no session key transmission is required. The
server key pair is not used in SSH2.
•
The
public-key local create dsa
command generates only a DSA host key pair. SSH1 does
not support the DSA algorithm.
•
The key modulus length must be less than 2048 bits when you use the
public-key local create
dsa
command on the SSH server.
•
The
public-key local create ecdsa
command generates only an ECDSA host key pair. SSH1
does not support the ECDSA algorithm.
Configuration procedure
To generate local key pairs on the SSH server:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Generate local key pairs.
public-key local create
{
dsa
|
ecdsa
{
secp256r1
|
secp384r1
}
|
rsa
}
By default, no local key pairs exist.
Enabling the Stelnet server
After you enable the Stelnet server on the device, clients can log in to the device through Stelnet.
To enable the Stelnet server:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the Stelnet server.
ssh server enable
By default, the Stelnet server is
disabled.
Enabling the SFTP server
After you enable the SFTP server on the device, clients can log in to the device through SFTP.