376
Configuring the device as an SCP client
SCP client configuration task list
Tasks at a glance
Remarks
(Required.)
Only required when the SCP server uses the
authentication method
publickey
,
password-publickey
, or
any
.
(Required.)
Establishing a connection to an SCP
N/A
(Optional.)
Establishing a connection to an SCP
N/A
Generating local key pairs
Generate local key pairs on the SCP client when the SCP server uses the authentication method
publickey
,
password-publickey
, or
any
.
Configuration restrictions and guidelines
When you generate local key pairs on an SCP client, follow these restrictions and guidelines:
•
Local DSA, ECDSA, and RSA key pairs for SSH use default names. You cannot assign names
to the key pairs.
•
The SCP client operating in FIPS mode supports only ECDSA and RSA key pairs.
•
The key modulus length must be less than 2048 bits when you generate a DSA key pair.
Configuration procedure
To generate local key pairs on the SCP client:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Generate local key pairs.
public-key local create
{
dsa
|
ecdsa
{
secp256r1
|
secp384r1
}
|
rsa
}
By default, no local key pairs exist
on an SCP client.
Establishing a connection to an SCP server
When you try to access an SCP server, the device must use the server's host public key to
authenticate the server. If the server's host public key is not configured on the device, the device will
notify you to confirm whether to continue with the access.
•
If you choose to continue, the device accesses the server and downloads the server's host
public key.
•
If you choose to not continue, the connection cannot be established.
As a best practice, configure the server's host public key on the device in an insecure network.
The client cannot establish connections to both IPv4 and IPv6 SCP servers.
To establish a connection to an IPv4 SCP server:
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...