HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 222

Configuring SCP, Overview, Configuring the switch as an SCP server

Page 222 highlights

Configuring SCP Overview Secure copy (SCP) is based on SSH2.0 and offers a secure approach to copying files. SCP uses SSH connections for copying files. The switch can act as the SCP server, allowing a user to log in to the switch for file upload and download. The switch can also act as an SCP client, enabling a user to log in from the switch to a remote server for secure file transfer. NOTE: When the switch acts as an SCP server, only one of the FTP, SFTP or SCP user can access the switch. Configuring the switch as an SCP server Step Command Remarks 1. Enter system view. system-view N/A 2. Configure the SSH server. For more information, see the security guide for your switch. N/A 3. Create an SSH user for a ssh user username service-type { all | scp } SCP client, set the authentication-type { password | { any | service type to all or scp, password-publickey | publickey } assign N/A and specify the publickey keyname work-directory authentication method. directory-name } • On the remote server (Details not 4. Create a user account shown.) and assign a working • On the switch: directory for the SSH user on the switch or a remote server if a. local-user b. password password authentication c. service-type ssh is used. d. authorization-attribute work-directory directory-name Skip this step if publickey authentication, whether with password authentication or not, is used. Make sure that the local user account has the name username as the username specified in the ssh user command. When you set the working directory for the user, follow these guidelines: • If only password authentication is used, the working directory specified in the ssh user command does not take effect. You must set the working directory on the remote server or in the local user account for the SSH user. • If publickey authentication, whether with password authentication or not, is used, you must set the working directory in the ssh user command. 212

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

212
Configuring SCP
Overview
Secure copy (SCP) is based on SSH2.0 and offers a secure approach to copying files.
SCP uses SSH connections for copying files. The switch can act as the SCP server, allowing a user to log
in to the switch for file upload and download. The switch can also act as an SCP client, enabling a user
to log in from the switch to a remote server for secure file transfer.
NOTE:
When the switch acts as an SCP server, only one of the FTP, SFTP or SCP user can access the switch.
Configuring the switch as an SCP server
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure the SSH
server.
For more information, see the security
guide for your switch.
N/A
3.
Create an SSH user for a
SCP client, set the
service type to
all
or
scp
,
and specify the
authentication method.
ssh user
username
service-type
{
all
|
scp
}
authentication-type
{
password
| {
any
|
password-publickey
|
publickey
}
assign
publickey
keyname
work-directory
directory-name
}
N/A
4.
Create a user account
and assign a working
directory for the SSH
user on the switch or a
remote server if
password authentication
is used.
On the remote server (Details not
shown.)
On the switch:
a.
local-user
b.
password
c.
service-type ssh
d.
authorization-attribute
work-directory
directory-name
Skip this step if
publickey
authentication,
whether
with
password
authentication
or
not, is used.
Make sure that the local user
account has the name username
as the username specified in the
ssh user
command.
When you set the working directory for the user, follow these guidelines:
If only password authentication is used, the working directory specified in the
ssh user
command
does not take effect. You must set the working directory on the remote server or in the local user
account for the SSH user.
If publickey authentication, whether with password authentication or not, is used, you must set the
working directory in the
ssh user
command.