Lifecyclepolicypublicuserkey - HP NonStop SSH 544701-014 Reference Manual

Table of Contents

Advertisement

and the values of parameters INTERVALPENDINGPRIVATEUSERKEY and
INTERVALLIVEPRIVATEUSERKEY.
Default
The default for this parameter is DISABLED resulting in the same behavior as before the introduction of this parameter.
Example
LIFECYCLEPOLICYPRIVATEUSERKEY FIXED
Considerations
Users with full SSHCOM access can set or modify KEY attributes LIVE-DATE and EXPIRE-DATE even
when the life-cycle policy for user private keys is set to FIXED.
See also:
INTERVALLIVEPRIVATEUSERKEY , INTERVALPENDINGPRIVATEUSERKEY

LIFECYCLEPOLICYPUBLICUSERKEY

This parameter controls the life-cycle of user public keys. If enabled, a 'not valid before date' and a 'not valid after date'
can be defined for each individual key. This can be achieved by setting the dates explicitly via entity USER
PUBLICKEY attributes LIVE-DATE and EXPIRE-DATE or implicitly via globally defined length of the key pending
time period after key addition and length of the period a key is in 'LIVE' state. Only a key in 'LIVE' state may be part of
a public key authentication of the user configured with the key.
Parameter Syntax
LIFECYCLEPOLICYPUBLICUSERKEY [DISABLED|FIXED|VARIABLE]
Arguments
DISABLED
Life-cycle control for user public keys will not be enabled. When a public key is added, it is immediately in
state 'LIVE' and it will never expire.
FIXED
Users without full SSHCOM access cannot set or alter KEY attributes LIVE-DATE and EXPIRE-DATE. Both
dates will be determined by the CREATION-DATE and the values of parameters
INTERVALPENDINGPUBLICUSERKEY and INTERVALLIVEPUBLICUSERKEY.
VARIABLE
Users with partial access can specify the LIVE-DATE and EXPIRE-DATE when adding a user public key or
when altering the public key. By not specifying these attributes in an ALTER USER PUBLICKEY command,
the values for LIVE-DATE and EXPIRE-DATE will be automatically set depending on the CREATION-DATE
and the values of parameters INTERVALPENDINGPUBLICUSERKEY and
INTERVALLIVEPUBLICUSERKEY.
Default
The default for this parameter is DISABLED resulting in the same behavior as before the introduction of this parameter.
Example
LIFECYCLEPOLICYPUBLICUSERKEY FIXED
Considerations
Users with full SSHCOM access can set or modify USER PUBLICKEY attributes LIVE-DATE and EXPIRE-
DATE even when the life-cycle policy for user public keys is set to FIXED.
HP NonStop SSH Reference Manual
Configuring and Running SSH2 • 79

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents