C H A P T E R
50-1
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
50
X.509v3 Certificates for SSH Authentication
The X.509v3 Certificates for SSH Authentication feature uses public key algorithm (PKI) for server and
user authentication, and allows the Secure Shell (SSH) protocol to verify the identity of the owner of a
key pair via digital certificates, signed and issued by a Certificate Authority (CA).
This module describes how to configure server and user certificate profiles for a digital certificate.
This module describes the feature and consists of these sections:
•
Prerequisites for X.509v3 Certificates for SSH Authentication, page 50-1
•
Restrictions for X.509v3 Certificates for SSH Authentication, page 50-2
•
Information About X.509v3 Certificates for SSH Authentication, page 50-2
•
How to Configure X.509v3 Certificates for SSH Authentication, page 50-3
•
Configuration Examples for 509v3 Certificates for SSH Authentication, page 50-5
•
Verifying Server and User Authentication Using Digital Certificates, page 50-6
•
Additional References for 509v3 Certificates for SSH Authentication, page 50-6
•
Feature Information for X.509v3 Certificates for SSH Authentication, page 50-8
Note
For complete syntax and usage information for the switch commands used in this chapter, see the
Cisco IOS Command Reference Guides for the Catalyst 4500 Series Switch
If a command is not in the
Cisco Catalyst 4500 Series Switch Command Reference
, you can locate it in
the
Cisco IOS Master Command List, All Releases
Prerequisites for X.509v3 Certificates for SSH Authentication
The X.509v3 Certificates for SSH Authentication feature replaces the
ip ssh server authenticate user
command with the
ip ssh server algorithm authentication
command. Configure the
default ip ssh
server authenticate user
command to remove the
ip ssh server authenticate user
command from the
configuration. The IOS secure shell (SSH) server will start using the
ip ssh server algorithm
authentication
command.
When you configure the
ip ssh server authenticate user
command, the following message is displayed:
“SSH command accepted; but this CLI will be deprecated soon. Please move to new CLI
ip ssh server
algorithm authentication
. Please configure the “
default ip ssh server authenticate user
” to make the
CLI ineffective.”
Содержание Catalyst 4500 Series
Страница 2: ......
Страница 4: ......
Страница 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...