HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 160

Destroying a local asymmetric key pair, Specifying the peer public key on the local device

Page 160 highlights

Destroying a local asymmetric key pair You may need to destroy a local asymmetric key pair and generate a new pair when an intrusion event has occurred, the storage media of the device is replaced, the asymmetric key has been used for a long time, or the local certificate expires. For more information about the local certificate, see "Configuring PKI." To destroy a local asymmetric key pair: Step 1. Enter system view. 2. Destroy a local asymmetric key pair. Command system-view public-key local destroy { dsa | rsa } Specifying the peer public key on the local device In some applications, such as SSH, to enable the local device to authenticate a peer device, specify the peer public key on the local device. The device supports up to 20 peer public keys. For information about displaying or exporting the host public key, see "Displaying or exporting the local host public key." Take one of the following methods to specify the peer public key on the local device: Method Import the public key from a public key file (recommended) Manually configure the public key-enter or copy the key data Prerequisites 3. Save the host public key of the intended asymmetric key pair in a file. 4. Transfer a copy of the file through FTP or TFTP in binary mode to the local device. • Display and record the public key of the intended asymmetric key pair. • If the peer device is an HP device, use the display public-key local public command to view and record its public key. A public key displayed by other methods for the HP device may not be in a correct format. Remarks During the import process, the system automatically converts the public key to a string in Public Key Cryptography Standards (PKCS) format. • The recorded public key must be in the correct format, or the manual configuration of a format-incompliant public key will fail. • Always use the first method if you are not sure about the format of the recorded public key. To import the host public key from a public key file to the local device: Step Command 1. Enter system view. system-view 2. Import the host public key from the public key file. public-key peer keyname import sshkey filename To manually configure the peer public key on the local device: 150

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

150
Destroying a local asymmetric key pair
You may need to destroy a local asymmetric key pair and generate a new pair when an intrusion event
has occurred, the storage media of the device is replaced, the asymmetric key has been used for a long
time, or the local certificate expires. For more information about the local certificate, see "
Configuring
PKI
."
To destroy a local asymmetric key pair:
Step
Command
1.
Enter system view.
system-view
2.
Destroy a local asymmetric key pair.
public-key local destroy
{
dsa
|
rsa
}
Specifying the peer public key on the local device
In some applications, such as SSH, to enable the local device to authenticate a peer device, specify the
peer public key on the local device. The device supports up to 20 peer public keys.
For information about displaying or exporting the host public key, see "
Displaying or exporting the local
host public key
."
Take one of the following methods to specify the peer public key on the local device:
Method
Prerequisites
Remarks
Import the public key from a public
key file (recommended)
3.
Save the host public key of the
intended asymmetric key pair
in a file.
4.
Transfer a copy of the file
through FTP or TFTP in binary
mode to the local device.
During the import process, the
system automatically converts the
public key to a string in Public Key
Cryptography Standards (PKCS)
format.
Manually configure the public
key—enter or copy the key data
Display and record the public
key of the intended asymmetric
key pair.
If the peer device is an HP
device, use the
display
public-key local public
command to view and record
its public key. A public key
displayed by other methods for
the HP device may not be in a
correct format.
The recorded public key must
be in the correct format, or the
manual configuration of a
format-incompliant public key
will fail.
Always use the first method if
you are not sure about the
format of the recorded public
key.
To import the host public key from a public key file to the local device:
Step
Command
1.
Enter system view.
system-view
2.
Import the host public key from the public key file.
public-key peer
keyname
import sshkey
filename
To manually configure the peer public key on the local device: