HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 196

Configuring whether first-time authentication is supported

Page 196 highlights

Step 1. Enter system view. Command system-view Remarks N/A • Specify a source IPv4 address or interface for the SSH client: Select either approach. ssh client source { ip ip-address | interface By default, an SSH client 2. Specify a source IP interface-type interface-number } uses the IP address of address or interface for the SSH client. • Specify a source IPv6 address or interface for the SSH client: the outbound interface defined by the route to ssh client ipv6 source { ipv6 ipv6-address | the SSH server to access interface interface-type interface-number } the SSH server. Configuring whether first-time authentication is supported When the switch acts as an SSH client and connects to the SSH server, you can configure whether the switch supports first-time authentication. • With first-time authentication, when an SSH client not configured with the server host public key accesses the server for the first time, the user can continue accessing the server, and save the host public key on the client. When accessing the server again, the client will use the saved server host public key to authenticate the server. • Without first-time authentication, a client not configured with the server host public key will refuse to access the server. To enable the client to access the server, you must configure the server host public key and specify the public key name for authentication on the client in advance. Enabling the switch to support first-time authentication Step 1. Enter system view. Command system-view 2. Enable the switch to support first-time authentication. ssh client first-time [ enable ] Remarks N/A Optional. By default, first-time authentication is supported on a client. Disabling first-time authentication For successful authentication of an SSH client not supporting first-time authentication, the server host public key must be configured on the client and the public key name must be specified. To disable first-time authentication: Step 1. Enter system view. 2. Disable first-time authentication support. 3. Configure the server host public key. Command system-view undo ssh client first-time See "Configuring a client public key" Remarks N/A By default, first-time authentication is supported on a client. The method for configuring the server host public key on the client is similar to that for configuring client public key on the server. 186

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

186
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify a source IP
address or interface for
the SSH client.
Specify a source IPv4 address or interface for the
SSH client:
ssh client source
{
ip
ip-address
|
interface
interface-type interface-number
}
Specify a source IPv6 address or interface for the
SSH client:
ssh client ipv6 source
{
ipv6
ipv6-address
|
interface
interface-type interface-number
}
Select either approach.
By default, an SSH client
uses the IP address of
the outbound interface
defined by the route to
the SSH server to access
the SSH server.
Configuring whether first-time authentication is supported
When the switch acts as an SSH client and connects to the SSH server, you can configure whether the
switch supports first-time authentication.
With first-time authentication, when an SSH client not configured with the server host public key
accesses the server for the first time, the user can continue accessing the server, and save the host
public key on the client. When accessing the server again, the client will use the saved server host
public key to authenticate the server.
Without first-time authentication, a client not configured with the server host public key will refuse to
access the server. To enable the client to access the server, you must configure the server host public
key and specify the public key name for authentication on the client in advance.
Enabling the switch to support first-time authentication
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the switch to support
first-time authentication.
ssh client first-time
[
enable
]
Optional.
By default, first-time authentication
is supported on a client.
Disabling first-time authentication
For successful authentication of an SSH client not supporting first-time authentication, the server host
public key must be configured on the client and the public key name must be specified.
To disable first-time authentication:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Disable first-time
authentication support.
undo ssh client first-time
By default, first-time authentication
is supported on a client.
3.
Configure the server host
public key.
See "
Configuring a client public
key
"
The method for configuring the
server host public key on the client
is similar to that for configuring
client public key on the server.