8-33
Configuring Secure Shell (SSH)
SSH Client and Secure Sessions
■
During “public-key” authentication, the client must use its private key to
authenticate itself to the server. There can be only one key pair on the
switch for the manager.
■
The private key should be passphrase protected for highest security; the
user is prompted to enter the passphrase.
■
The private key can be configured by copying it to the SSH client switch
(using the
copy
command).
■
If the public-key authentication fails or the client has not been configured
with a key pair, the “password” method of authentication is used and the
user is prompted for a password.
■
Successful TACACS or RADIUS logins will give the user either operator
or manager privileges. This is important if there are chained SSH sessions.
Copying Client Key Files
Only one ssh client key for authenticating the manager is allowed on a switch.
The
copy
command allows you to copy the client key files using
sftp, tftp, and
usb or xmodem
, allowing encryption and authentication through SSH. There is
no way to generate the private key on the switch; it must be copied onto the
switch.
To load the client’s private key onto the switch, use one of these commands.
Syntax
:
copy sftp ssh-client-key [user <username> | <username@>] <hostname
| IPv4 | IPv6>
<private-key-filename
> [port <
tcp-port-num
>]
copy tftp ssh-client-key< hostname | IPv4 | IPv6> <
private-key-filename
>
copy usb ssh-client-key <
private-key-filename
>
copy xmodem ssh-client-key
Copies the client key file <
private-key-filename
> onto the
switch.
ssh-client-key:
The client key file being copied to the
switch. The file must contain an RSA or DSA key.
[user <username | username@>]:
Optional; there must be
configured usernames for Operator and Manager.
If no
username
is specified, the client’s current
username
is used. There will be a prompt for a password if needed.
hostname:
Specifies the hostname of the SFTP or TFTP
server.
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......