Purpose
Command or Action
Defines the order of host key algorithms. Only the configured
algorithm is negotiated with the Secure Shell (SSH) client.
ip ssh server algorithm hostkey
{
x509v3-ssh-rsa
[
ssh-rsa
] |
ssh-rsa
[
x509v3-ssh-rsa
]}
Step 3
The IOS SSH server must have at least one configured host
key algorithm:
Note
•
x509v3-ssh-rsa
—
certificate-based authentication
•
ssh-rsa
—
public key-based authentication
Example:
Switch(config)# ip ssh server algorithm
hostkey x509v3-ssh-rsa
Configures server and user certificate profiles and enters SSH
certificate profile configuration mode.
ip ssh server certificate profile
Example:
Switch(config)# ip ssh server certificate
profile
Step 4
Configures server certificate profile and enters SSH server certificate
profile server configuration mode.
server
Example:
Switch(ssh-server-cert-profile)# server
Step 5
•
The server profile is used to send out the certificate of the server
to the SSH client during server authentication.
Attaches the public key infrastructure (PKI) trustpoint to the server
certificate profile.
trustpoint sign PKI-trustpoint-name
Example:
Switch(ssh-server-cert-profile-server)#
trustpoint sign trust1
Step 6
•
The SSH server uses the certificate associated with this PKI
trustpoint for server authentication.
(Optional) Sends the Online Certificate Status Protocol (OCSP)
response or OCSP stapling along with the server certificate.
ocsp-response include
Example:
Switch(ssh-server-cert-profile-server)#
ocsp-response include
Step 7
By default, no OCSP response is sent along with the server
certificate.
Note
Exits SSH server certificate profile server configuration mode and
returns to privileged EXEC mode.
end
Example:
Switch(ssh-server-cert-profile-server)#
end
Step 8
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1120
How to Configure X.509v3 Certificates for SSH Authentication
Содержание Catalyst 2960 Series
Страница 78: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches lxxviii Contents ...
Страница 96: ......
Страница 184: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 102 Additional References ...
Страница 195: ...P A R T II IP Multicast Routing Configuring IGMP Snooping and Multicast VLAN Registration page 115 ...
Страница 196: ......
Страница 250: ......
Страница 292: ......
Страница 488: ......
Страница 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Страница 590: ......
Страница 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Страница 620: ......
Страница 749: ...P A R T VIII Routing Configuring IP Unicast Routing page 669 Configuring IPv6 First Hop Security page 677 ...
Страница 750: ......
Страница 796: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 714 Additional References ...
Страница 856: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 774 Additional References ...
Страница 1400: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1318 Additional References ...
Страница 1546: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1464 Auto Identity ...
Страница 1596: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1514 Additional References ...
Страница 1604: ......
Страница 1740: ......
Страница 1764: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1682 Additional References ...
Страница 1942: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1860 cli_write ...
Страница 1950: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1868 context_save ...
Страница 2058: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1976 event_register_wdsysmon ...
Страница 2076: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1994 smtp_subst ...
Страница 2090: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2008 sys_reqinfo_syslog_history ...
Страница 2104: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2022 unregister_counter ...
Страница 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Страница 2106: ......
Страница 2118: ......
Страница 2164: ......