HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 128

Configuring a peer public key, Importing a peer host public key from a public key file

Page 128 highlights

Configuring a peer public key To encrypt information sent to a peer device or authenticate the digital signature of the peer device, you must configure the public key of the peer device on the local device. Table 8 Peer public key configuration methods Method Import the peer public key from a public key file (recommended). Manually enter (type or copy) the peer public key. Prerequisites 1. Save the host public key in a file on the peer device. 2. Get the file from the peer device, for example, by using FTP or TFTP in binary mode. Display and record the public key on the peer device. IMPORTANT: If the peer device is an HP device, use the display public-key local public command to display the public key. The format of the public key displayed in any other way might be incorrect. Remarks The system automatically converts the imported public key to a string in the Public Key Cryptography Standards (PKCS) format. • If the key is not in the correct format, the system discards the key and displays an error message. If the key is valid, for example, the key displayed by the display public-key local public command, the system saves the key. • Always use the first method if you are not sure of the format of the recorded public key. For information about displaying or exporting host public keys, see "Distributing a local host public key." HP recommends that you configure no more than 20 peer public keys on the device. Importing a peer host public key from a public key file Step 1. Enter system view. 2. Import a peer host public key from a public key file. Command system-view public-key peer keyname import sshkey filename Remarks N/A By default, no peer host public key exists. Entering a peer public key Step 1. Enter system view. 2. Specify a name for the peer public key and enter public key view. Command system-view public-key peer keyname 3. Type or copy the key. N/A 4. Return to system view. peer-public-key end Remarks N/A By default, no peer host public key exists. You can use spaces and carriage returns, but the system does not save them. When you exit public key view, the system automatically saves the public key. 119

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

119
Configuring a peer public key
To encrypt information sent to a peer device or authenticate the digital signature of the peer device, you
must configure the public key of the peer device on the local device.
Table 8
Peer public key configuration methods
Method
Prerequisites
Remarks
Import the peer public key
from a public key file
(recommended).
1.
Save the host public key in a file
on the peer device.
2.
Get the file from the peer device,
for example, by using FTP or
TFTP in binary mode.
The system automatically converts the
imported public key to a string in the
Public Key Cryptography Standards
(PKCS) format.
Manually enter (type or copy)
the peer public key.
Display and record the public key on
the peer device.
IMPORTANT:
If the peer device is an HP device, use
the
display public-key local public
command to display the public key.
The format of the public key displayed
in any other way might be incorrect.
If the key is not in the correct
format, the system discards the key
and displays an error message. If
the key is valid, for example, the
key displayed by the
display
public-key local public
command,
the system saves the key.
Always use the first method if you
are not sure of the format of the
recorded public key.
For information about displaying or exporting host public keys, see "
Distributing a local host public key
."
HP recommends that you configure no more than 20 peer public keys on the device.
Importing a peer host public key from a public key file
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Import a peer host public key
from a public key file.
public-key peer
keyname
import sshkey
filename
By default, no peer host
public key exists.
Entering a peer public key
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify a name for the peer
public key and enter public
key view.
public-key peer
keyname
By default, no peer host public key exists.
3.
Type or copy the key.
N/A
You can use spaces and carriage returns,
but the system does not save them.
4.
Return to system view.
peer-public-key end
When you exit public key view, the
system automatically saves the public
key.