3Com E4500-24 Cli Configuration Manual page 663

Hp e4500-24: user guide
Table of Contents

Advertisement

Configuring whether first-time authentication is supported
When the device connects to the SSH server as an SSH client, you can configure whether the device
supports first-time authentication.
With first-time authentication enabled, an SSH client that is not configured with the server host
public key can continue accessing the server when it accesses the server for the first time, and it
will save the host public key on the client for use in subsequent authentications.
With first-time authentication disabled, an SSH client that is not configured with the server host
public key will be denied of access to the server. To access the server, a user must configure in
advance the server host public key locally and specify the public key name for authentication.
Follow these steps to enable the device to support first-time authentication:
To do...
Enter system view
Enable the device to support
first-time authentication
Follow these steps to disable first-time authentication support:
To do...
Enter system view
Disable first-time authentication
support
Configure server public key
Specify the host key name of
the server
With first-time authentication enabled, an SSH client that is not configured with the SSH server's host
public key saves the host public key sent by the server without authenticating the server. Attackers may
exploit the vulnerability to initiate man-in-middle attacks by acting as an SSH server. Therefore, it is
recommended to disable first-time authentication unless you are sure that the SSH server is reliable.
Specifying a source IP address/interface for the SSH client
You can configure a souce IP address or the souce IP address by specifying the corresponding
interface for the client to use to access the SSH server. This improves the service manageability when
the SSH client has multiple IP addresses and interfaces
Use the command...
system-view
ssh client first-time enable
Use the command...
system-view
undo ssh client first-time
Refer to
Configuring the Public
Key of a Client on the Server
ssh
client
{
server-ip
server-name
}
publickey keyname
1-20
Remarks
Optional
By default, the client is enabled
to run first-time authentication.
Remarks
Required
By default, the client is enabled
to run first-time authentication.
Required
The method of configuring
server public key on the client is
similar to that of configuring
client public key on the server.
|
assign
Required

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500

Table of Contents