HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 194

Configuration procedure, Setting the SSH management parameters

Page 194 highlights

Configuration procedure To configure an SSH user and specify the service type and authentication method: Step 1. Enter system view. 2. Create an SSH user, and specify the service type and authentication method. Command Remarks system-view N/A • For Stelnet users: ssh user username service-type stelnet authentication-type { password | { any | password-publickey | publickey } assign publickey keyname } • For all users, SCP or SFTP users: Use either command. ssh user username service-type { all | scp | sftp } authentication-type { password | { any | password-publickey | publickey } assign publickey keyname work-directory directory-name } Setting the SSH management parameters SSH management includes: • Enabling the SSH server to be compatible with SSH1 client • Setting the RSA server key pair update interval, applicable to users using SSH1 client • Setting the SSH user authentication timeout period • Setting the maximum number of SSH authentication attempts Setting these parameters can help avoid malicious guessing at and cracking of the keys and usernames, securing your SSH connections. IMPORTANT: Authentication fails if the number of authentication attempts (including both publickey and password authentication) exceeds that specified in the ssh server authentication-retries command. To set the SSH management parameters: Step 1. Enter system view. 2. Enable the SSH server to support SSH1 clients. Command system-view ssh server compatible-ssh1x [ enable ] 3. Set the RSA server key pair update interval. ssh server rekey-interval hours Remarks N/A Optional. By default, the SSH server supports SSH1 clients. Optional. By default, the interval is 0, and the RSA server key pair is not updated. 184

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

184
Configuration procedure
To configure an SSH user and specify the service type and authentication method:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an SSH user, and
specify the service type and
authentication method.
For Stelnet users:
ssh user
username
service-type
stelnet
authentication-type
{
password
| {
any
|
password-publickey
|
publickey
}
assign publickey
keyname
}
For all users, SCP or SFTP users:
ssh user
username
service-type
{
all
|
scp
|
sftp
}
authentication-type
{
password
| {
any
|
password-publickey
|
publickey
}
assign publickey
keyname
work-directory
directory-name
}
Use either command.
Setting the SSH management parameters
SSH management includes:
Enabling the SSH server to be compatible with SSH1 client
Setting the RSA server key pair update interval, applicable to users using SSH1 client
Setting the SSH user authentication timeout period
Setting the maximum number of SSH authentication attempts
Setting these parameters can help avoid malicious guessing at and cracking of the keys and usernames,
securing your SSH connections.
IMPORTANT:
Authentication fails if the number of authentication attempts (including both publickey and password
authentication) exceeds that specified in the
ssh server authentication-retries
command.
To set the SSH management parameters:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the SSH server to
support SSH1 clients.
ssh server compatible-ssh1x
[
enable
]
Optional.
By default, the SSH server supports
SSH1 clients.
3.
Set the RSA server key pair
update interval.
ssh server rekey-interval
hours
Optional.
By default, the interval is 0, and the
RSA server key pair is not updated.