Description
Use the ssh user command to create an SSH user and specify the service type and authentication
mode.
Use the undo ssh user command to delete an SSH user.
Note that:
For a publickey authentication user, you must configure the username and the public key on the
device. For a password authentication user, you can configure the account information on either
the device or the remote authentication server such as a RADIUS server.
If you use the ssh user command to configure a public key for a user who has already had a public
key, the new one overwrites the old one.
Authentication mode and public key configuration takes effect only for users logging in after the
configuration..
If an SFTP user has been assigned a public key, it is necessary to set a working folder for the user.
The working folder of an SFTP user is subject to the user authentication mode. For a user using
only password authentication, the working folder is the AAA authorized one. For a user using only
publickey authentication or using both the publickey and password authentication modes, the
working folder is the one set by using the ssh user command.
Related commands: display ssh user-information.
Examples
# Create an SSH user named user1, setting the service type as sftp, the authentication mode as
publickey, the work folder of the SFTP server as flash, and assigning a public key named key1 to the
user.
<Sysname> system-view
[Sysname] ssh user user1 service-type sftp authentication-type publickey assign publickey
key1 work-directory flash:
ssh2
Syntax
ssh2 server [ port-number ] [ prefer-ctos-cipher { 3des | aes128 | des } | prefer-ctos-hmac { md5 |
md5-96 | sha1 | sha1-96 } | prefer-kex { dh-group-exchange | dh-group1 | dh-group14 } |
prefer-stoc-cipher { 3des | aes128 | des } | prefer-stoc-hmac { md5 | md5-96 | sha1 | sha1-96 } ] *
View
User view
Default Level
0: Visit level
Parameters
server: IPv4 address or name of the server, a string of 1 to 20 characters.
port-number: Port number of the server, in the range 0 to 65535. The default is 22.
prefer-ctos-cipher: Preferred encryption algorithm from client to server, defaulted to aes128.
3des: Encryption algorithm 3des-cbc.
1-25
Need help?
Do you have a question about the S7906E and is the answer not in the manual?