Configuring Secure Shell (SSH)
Terminology
Switch SSH and User Password Authentication .
This option is a subset
of the client public-key authentication shown in figure 7-1. It occurs if the
switch has SSH enabled but does not have login access (
login public-key
)
configured to authenticate the client’s key. As in figure 7-1, the switch authen
ticates itself to SSH clients. Users on SSH clients then authenticate themselves
to the switch (login and/or enable levels) by providing passwords stored
locally on the switch or on a or RADIUS server. However, the client
does not use a key to authenticate itself to the switch.
ProCurve
Switch
(SSH
Server)
SSH
Client
Work-
Station
1. Switch-to-Client SSH
2. User-to-Switch (login password and
enable password authentication)
options:
– Local
–
Figure 7-2. Switch/User Authentication
Terminology
■
SSH Server:
An ProCurve switch with SSH enabled.
■
Key Pair:
A pair of keys generated by the switch or an SSH client
application. Each pair includes a public key, that can be read by anyone
and a private key held internally in the switch or by a client.
■
PEM (Privacy Enhanced Mode):
Refers to an ASCII-formatted client
public-key that has been encoded for portability and efficiency. SSHv2
client public-keys are typically stored in the PEM format. See figure 7-3
for an example of PEM-encoded ASCII keys.
■
Private Key:
An internally generated key used in the authentication
process. A private key generated by the switch is not accessible for
viewing or copying. A private key generated by an SSH client application
is typically stored in a file on the client device and, together with its public
key counterpart, can be copied and stored on multiple devices.
■
Public Key:
An internally generated counterpart to a private key. A
device’s public key is used to authenticate the device to other devices.
■
Enable Level:
Manager privileges on the switch.
■
Login Level:
Operator privileges on the switch.
7-3
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...