Spectracom Corporation
Model 9289
NetClock/NTP Network Time Provider Instruction Manual
3-71
delete the old keys, then select the create host keys checkbox and enter the key sizes you
desire. Then select the submit button at the bottom of the screen.
Spectracom secure products typically have their initial Host Keys created at the factory. The
default key size for all key types is 1024. Host Key sizes can vary between 768 and 4096 bits.
The recommended key size is 1024. Though many key sizes are supported, it is recommended
that users select key sizes that are powers of 2 or divisible by 2. The most popular sizes are
768, 1024, and 2048. Large key sizes up to 4096 are supported, but may take ten minutes or
more to generate.
Host Keys are generated in the background. Creating RSA and DSA keys, each with 1024 bits
length, typically takes about 30 seconds. Keys are created in the order of RSA, DSA and finally
RSA1. When the keys are created you can successfully make SSH client connections. If the unit
is rebooted with Host Key creation in progress or the unit is booted and no host keys exist the
key generation process is restarted. The key generation process uses either the previously
specified key sizes or if a key size is undefined it defaults to 1024. A key with a zero length or
blank key size field is not created.
Note also that when you delete a Host Key and recreate a new one, SSH client sessions will
warn you that the host key has changed for this particular IP address. The user will either have
to override the warning and accept the new Public Host Key and start a new connection or they
may need to remove the old Host Public Key from their client system and accept the new Host
Public Key. Please consult your specific SSH client’s software’s documentation.
The SSH client utilities SSH, SCP, and SFTP allow for several modes of user authentication.
SSH allows the user to remotely login or transfer files by identifying the user’s account and the
target machines IP address. Users can be authenticated by either using their account
passwords or by using a Public Private Key Pair. Users keep their private key secret within their
workstations or network user accounts and provide the NetClock a copy of their public key. The
modes of authentication supported include:
•
Either Public Key with Passphrase or Login Account Password
•
Login Account Password only
•
Public Key with Passphrase only
The first option allows users to login using either method. This is the default. Whichever mode
works is allowed for logging in. If the Public Key is not correct or the Passphrase is not valid the
user is then prompted for the login account password. The second option simply skips
public/private key authentication and immediately prompts the user for password over a secure
encrypted session avoiding sending passwords in the clear. Finally the last option requires the
user to load a public key into the NetClock. This public key must match the private key found in
the users account and be accessible to the SSH, SCP, or SFTP client program. The user must
then enter the Passphrase after authentication of the keys to provide the second factor for 2-
factor authentication.
SSH using public/private key authentication is the most secure method of authenticating users
for SSH, SCP or SFTP sessions.
The web browser user interface provides the means for the user to view and edit the
authorized_keys file, to add Public Keys. Using FTP, SCP, or SFTP the user may also retrieve
the authorized_keys file from the .ssh directory.
Summary of Contents for 9289
Page 18: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 1 8...
Page 36: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 2 18...
Page 154: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 3 118...