Brocade Communications Systems Brocate Ethernet Access Switch 6910 User Manual

Page 217

Advertising
background image

Brocade 6910 Ethernet Access Switch Configuration Guide

167

53-1002581-01

Secure Shell

9

To use the SSH server, complete these steps:

1. Generate a Host Key Pair – Use the

ip ssh crypto host-key generate

command to create a host

public/private key pair.

2. Provide Host Public Key to Clients – Many SSH client programs automatically import the host

public key during the initial connection setup with the switch. Otherwise, you need to manually
create a known hosts file on the management station and place the host public key in it. An
entry for a public key in the known hosts file would appear similar to the following example:

10.1.0.54 1024 35
15684995401867669259333946775054617325313674890836547254
15020245593199868544358361651999923329781766065830956
108259132128902337654680172627257141342876294130119619556678259566410
486957427888146206519417467729848654686157177393901647793559423035774
1309802273708779454524083971752646358058176716709574804776117

3. Import Client’s Public Key to the Switch – Use the

copy

tftp public-key

command to copy a file

containing the public key for all the SSH client’s granted management access to the switch.
(Note that these clients must be configured locally on the switch with the

username

command.) The clients are subsequently authenticated using these keys. The current firmware
only accepts public key files based on standard UNIX format as shown in the following example
for an RSA key:

1024 35
134108168560989392104094492015542534763164192187295892114317388005553
616163105177594083868631109291232226828519254374603100937187721199696
317813662774141689851320491172048303392543241016379975923714490119380
06090253948408482717819437228840253311595213486102290297898272135326
7131629432532818915045306393916643 [email protected]

4. Set the Optional Parameters – Set other optional parameters, including the authentication

timeout, the number of retries, and the server key size.

5. Enable SSH Service – Use the

ip ssh server

command to enable the SSH server on the switch.

6. Authentication – One of the following authentication methods is employed:

Password Authentication (for SSH v1.5 or V2 Clients)

a. The client sends its password to the server.

b. The switch compares the client's password to those stored in memory.

c. If a match is found, the connection is allowed.

NOTE

To use SSH with only password authentication, the host public key must still be given to the client,
either during initial connection or manually entered into the known host file. However, you do not
need to configure the client's keys.

Public Key Authentication – When an SSH client attempts to contact the switch, the SSH server
uses the host key pair to negotiate a session key and encryption method. Only clients that have
a private key corresponding to the public keys stored on the switch can access it. The following
exchanges take place during this process:

Advertising