HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 158

Creating a local asymmetric key pair, Displaying or exporting the local host public key

Page 158 highlights

Task Configuring a local asymmetric key pair on the local device Creating a local asymmetric key pair Displaying or exporting the local host public key Destroying a local asymmetric key pair Specifying the peer public key on the local device Remarks Perform the tasks as needed. Creating a local asymmetric key pair When you create an asymmetric key pair on the local device, follow these guidelines: • Create an asymmetric key pair of the proper type to work with a target application. • After you enter the command, specify a proper modulus length for the key pair. The following table compares the three types of key pairs. Table 10 A comparison between different types of asymmetric key pairs Type RSA DSA Number of key pairs Modulus length Two key pairs, one server key pair and one host key par. Each key pair comprises a public key and a private key One key pair, the host key pair 512 to 2048 bits 1024 by default Remarks To achieve high security, specify at least 768 bits. IMPORTANT: Only SSH1.5 uses the RSA server key pair. To create a local asymmetric key pair: Step Command Remarks 1. Enter system view. system-view N/A By default, no asymmetric key pair is created. 2. Create a local asymmetric key pair. public-key local create { dsa | rsa } Key pairs created with the public-key local create command are saved automatically and can survive system reboots. Displaying or exporting the local host public key In some applications, such as SSH, to allow your local device to be authenticated by a peer device through digital signature, you must display or export the local host public key, which will then be specified on the peer device. To display or export the local host public key, choose one of the following methods: • Displaying and recording the host public key information • Displaying the host public key in a specific format and saving it to a file • Exporting the host public key in a specific format to a file 148

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

148
Task
Remarks
Configuring a local
asymmetric key pair
on the local device
Creating a local asymmetric key pair
Perform the tasks as
needed.
Displaying or exporting the local host public key
Destroying a local asymmetric key pair
Specifying the peer public key on the local device
Creating a local asymmetric key pair
When you create an asymmetric key pair on the local device, follow these guidelines:
Create an asymmetric key pair of the proper type to work with a target application.
After you enter the command, specify a proper modulus length for the key pair. The following table
compares the three types of key pairs.
Table 10
A comparison between different types of asymmetric key pairs
Type
Number of key pairs
Modulus length
Remarks
RSA
Two key pairs, one server key pair and one
host key par. Each key pair comprises a
public key and a private key
512 to 2048 bits
1024 by default
To achieve high
security, specify at least
768 bits.
DSA
One key pair, the host key pair
IMPORTANT:
Only SSH1.5 uses the RSA server key pair.
To create a local asymmetric key pair:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a local asymmetric key
pair.
public-key local create
{
dsa
|
rsa
}
By default, no asymmetric key pair
is created.
Key pairs created with the
public-key local create
command
are saved automatically and can
survive system reboots.
Displaying or exporting the local host public key
In some applications, such as SSH, to allow your local device to be authenticated by a peer device
through digital signature, you must display or export the local host public key, which will then be
specified on the peer device.
To display or export the local host public key, choose one of the following methods:
Displaying and recording the host public key information
Displaying the host public key in a specific format and saving it to a file
Exporting the host public key in a specific format to a file