Generating A Dsa Or Rsa Key Pair; Enabling The Ssh Server Function - HP 5120 EI Switch Series Configuration Manual

Hide thumbs Also See for 5120 EI Switch Series:
Table of Contents

Advertisement

Task

Generating a DSA or RSA key pair

Enabling the SSH server function

Configuring the user interfaces for SSH clients
Configuring a client public key
Configuring an SSH user
Setting the SSH management parameters
Generating a DSA or RSA key pair
In the key and algorithm negotiation stage, the DSA or RSA key pair is required to generate the session
ID and for the client to authenticate the server.
Follow these steps to generate a DSA or RSA key pair on the SSH server:
To do...
Enter system view
Generate a DSA or RSA key pair
NOTE:
For more information about the public-key local create command, see the
To support SSH clients using different types of key pairs, generate both DSA and RSA key pairs on the SSH
server.
The public-key local create rsa command generates a server key pair and a host key pair. Each of the key pairs
consists of a public key and a private key. The public key in the server key pair of the SSH server is used in SSH1
to encrypt the session key for secure transmission of the key. As SSH2.0 uses the DH algorithm to generate the
session key on the SSH server and client respectively, no session key transmission is required in SSH2.0 and the
server key pair is not used.
The length of the modulus of RSA server keys and host keys must be in the range 512 to 2048 bits. Some SSH2.0
clients require that the length of the key modulus be at least 768 bits on the SSH server side.
The public-key local create dsa command generates only the host key pair. SSH1 does not support the DSA
algorithm.
The length of the modulus of DSA host keys must be in the range 512 to 2048 bits. Some SSH2.0 clients require
that the length of the key modulus be at least 768 bits on the SSH server side.
Enabling the SSH server function
Follow these steps to enable the SSH server function:
To do...
Enter system view
Remarks
Required
Required
Required
Required for publickey authentication users and
optional for password authentication users
Optional
Optional
Use the command...
system-view
public-key local create { dsa | rsa
}
Use the command...
system-view
211
Remarks
Required
By default, neither DSA key pair
nor RSA key pair exists.
Security Command Reference
Remarks
.

Advertisement

Table of Contents
loading

Table of Contents