System Management Commands
4-35
4
The clients are subsequently authenticated using these keys. The current
firmware only accepts public key files based on standard UNIX format as shown
in the following example for an RSA Version 1 key:
5.
1024 35
13410816856098939210409449201554253476316419218729589211431738
80
05553616163105177594083868631109291232226828519254374603100937
187721199696317813662774141689851320491172048303392543241016379
975923714490119380060902539484084827178194372288402533115952134
861022902978982721353267131629432532818915045306393916643
[email protected]
6.
Set the Optional Parameters – Set other optional parameters, including the
authentication timeout, the number of retries, and the server key size.
7.
Enable SSH Service – Use the
ip ssh server
command to enable the SSH
server on the switch.
8.
Configure Challenge-Response Authentication – When an SSH client attempts
to contact the switch, the SSH server uses the host key pair to negotiate a
session key and encryption method. Only clients that have a private key
corresponding to the public keys stored on the switch can gain access. The
following exchanges take place during this process:
9.
The client sends its public key to the switch.
10. The switch compares the client's public key to those stored in memory.
11. If a match is found, the switch uses the public key to encrypt a random
sequence of bytes, and sends this string to the client.
12. The client uses its private key to decrypt the bytes, and sends the decrypted
bytes back to the switch.
13. The switch compares the decrypted bytes to the original bytes it sent. If the two
sets match, this means that the client's private key corresponds to an
authorized public key, and the client is authenticated.
Note:
To use SSH with only password authentication, the host public key must still be
given to the client, either during initial connection or manually entered into the
known host file. However, you do not need to configure the client’s keys.
ip ssh server
This command enables the Secure Shell (SSH) server on this switch. Use the
no
form to disable this service.
Syntax
[no] ip ssh server
Summary of Contents for 8124PL2
Page 1: ...MANAGEMENT GUIDE TigerSwitchTM 10 100 1000 24 Port Managed Switch with PoE SMC8124PL2 ...
Page 2: ......
Page 20: ...xvi Contents ...
Page 27: ...xxiii Figures ...
Page 35: ...Introduction 1 8 1 ...
Page 45: ...Initial Configuration 2 10 2 ...
Page 148: ...Port Configuration 3 103 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Page 473: ...Command Line Interface 4 240 4 ...
Page 477: ...Software Specifications A 4 A ...
Page 489: ...Index Index 4 menu list 3 3 panel display 3 3 ...
Page 490: ......