106 Configuring standard security features
Configuring SSH authentication
Incoming authentication is used when the remote host needs to authenticate to the switch. Outgoing
authentication is used when the switch needs to authenticate to a server or remote host and is more
commonly used for the
configUpload
command. Both password and public key authentication can
coexist on the switch.
After the allowed-user is configured, the remaining setup steps must be completed by the allowed-user.
1.
Log in to the switch as the default admin.
2.
Change the allowed-user’s role to admin, if applicable.
switch:admin>
userconfig --change username -r admin
where
username
is the name of the user you want to perform SSH public key authentication, import,
export, and delete keys.
3.
Set up the allowed-user by typing the following command:
switch:admin>
sshutil allowuser username
where
username
is the name of the user you want to perform SSH public key authentication, import,
export, and delete keys.
4.
Generate a key pair for host-to-switch (incoming) authentication by logging in to your host as admin,
verifying that SSH v2 is installed and working (see your host’s documentation as necessary), and
typing the following command:
ssh-keygen -t dsa
If you need to generate a key pair for outgoing authentication, skip steps 4 and 5 and proceed to step
6.
Example: RSA/DSA key pair generation
alloweduser@mymachine:
ssh-keygen -t dsa
Generating public/private dsa key pair.
Enter file in which to save the key (
/users/alloweduser/.ssh/id_dsa
):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /users/alloweduser/.ssh/id_dsa.
Your public key has been saved in /users/alloweduser/.ssh/id_dsa.pub.
The key fingerprint is:
32:9f:ae:b6:7f:7e:56:e4:b5:7a:21:f0:95:42:5c:d1 alloweduser@mymachine
5.
Import the public key to the switch by logging in to the switch as the allowed-user and entering the
following command:
sshUtil importpubkey
Respond to the prompts as follows:
Example: Adding the public key to the switch
IP address
Enter the IP address of the switch. IPv6 is supported by
sshUtil
.
remote directory
Enter the path to the remote directory where the public key is stored.
public key name
Enter the name of the public key.
login name
Enter the name of the user granted access to the host.
password
Enter the password for the host.
Содержание A7533A - Brocade 4Gb SAN Switch Base
Страница 1: ...HP StorageWorks Fabric OS 6 2 administrator guide Part number 5697 0016 Edition May 2009 ...
Страница 24: ...24 ...
Страница 99: ...Fabric OS 6 2 administrator guide 99 ...
Страница 100: ...100 Managing user accounts ...
Страница 118: ...116 Configuring standard security features ...
Страница 164: ...162 Configuring advanced security features ...
Страница 234: ...232 Installing and maintaining firmware ...
Страница 268: ...266 Administering advanced zoning ...
Страница 284: ...282 Configuring Enterprise class platforms ...
Страница 292: ...290 Routing traffic ...
Страница 294: ...292 Interoperability for merged SANs ...
Страница 302: ...300 Configuring the Distributed Management Server ...
Страница 334: ...332 iSCSI gateway service ...
Страница 340: ...338 Administering NPIV ...
Страница 407: ...Fabric OS 6 2 administrator guide 405 ...
Страница 408: ...406 Using the FC FC routing service ...
Страница 438: ...434 Administering extended fabrics ...
Страница 460: ...456 Administering ISL trunking ...
Страница 498: ...494 Configuring and monitoring FCIP extension services 556200 Bps 30s avg 491394 Bps lifetime avg ...
Страница 516: ...512 FICON fabrics ...
Страница 526: ...522 Configuring and monitoring FICON Extension Services ...
Страница 540: ...536 Configuring the PID format ...
Страница 544: ...540 Understanding legacy password behavior ...
Страница 546: ...542 Mixed fabric configurations for non merge SANs ...
Страница 550: ...546 Migrating from an MP Router to a 400 MP Router ...
Страница 558: ...554 Inband Management ...
Страница 572: ...568 ...