311
To disable first-time authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Disable first-time
authentication support.
undo ssh client first-time
By default, first-time authentication
is supported on a client.
3.
Configure the server host
public key.
See "
The method for configuring the
server host public key on the client
is similar to that for configuring
client public key on the server.
4.
Specify the host public key
name of the server.
ssh client
authentication server
server
assign publickey
keyname
N/A
Establishing a connection between the SSH client and server
Task Command
Remarks
Establish a
connection
between the SSH
client and the
server, and specify
the public key
algorithm,
preferred
encryption
algorithm,
preferred HMAC
algorithm and
preferred key
exchange
algorithm.
•
For an IPv4 server:
{
In non-FIPS mode:
ssh2
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
identity-key
{
dsa
|
rsa
} |
prefer-ctos-cipher
{
3des
|
aes128
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} |
prefer-kex
{
dh-group-exchange
|
dh-group1
|
dh-group14
} |
prefer-stoc-cipher
{
3des
|
aes128
|
des
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] *
{
In FIPS mode:
ssh2
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
identity-key
rsa
|
prefer-ctos-cipher
{
aes128
|
aes256
} |
prefer-ctos-hmac
{
sha1
|
sha1-96
}
|
prefer-kex dh-group14
|
prefer-stoc-cipher
{
aes128
|
aes256
} |
prefer-stoc-hmac
{
sha1
|
sha1-96
} ] *
•
For an IPv6 server:
{
In non-FIPS mode:
ssh2 ipv6
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
identity-key
{
dsa
|
rsa
} |
prefer-ctos-cipher
{
3des
|
aes128
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} |
prefer-kex
{
dh-group-exchange
|
dh-group1
|
dh-group14
} |
prefer-stoc-cipher
{
3des
|
aes128
|
des
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] *
{
In FIPS mode:
ssh2 ipv6
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
identity-key rsa
|
prefer-ctos-cipher
{
aes128
|
aes256
} |
prefer-ctos-hmac
{
sha1
|
sha1-96
}
|
prefer-kex dh-group14
|
prefer-stoc-cipher
{
aes128
|
aes256
} |
prefer-stoc-hmac
{
sha1
|
sha1-96
} ] *
Use one of the
commands in user
view.