beautypg.com

Enabling dsa public key authentication – Brocade Multi-Service IronWare Security Configuration Guide (Supporting R05.6.00) User Manual

Page 266

background image

248

Multi-Service IronWare Security Configuration Guide

53-1003035-02

SSH server version 2 support

5

NOTE

When one public-key file already exists, downloading a second public-key file will cause the second
public-key file to overwrite the existing one. Downloading a public-key file when a public-key file
already exists also erases currently loaded public-keys in the active configuration and loads only
keys in the newly downloaded file.

To cause a public key file called pkeys.txt to be loaded from a TFTP server each time the device is
booted, enter a command such as the following.

Brocade(config)# ip ssh pub-key-file tftp 192.168.1.234 pkeys.txt

Syntax: ip ssh pub-key-file tftp ipv6 ipv6-addr | tftp-server-ip-addr filename [remove]

The tftp-server-ip-addr variable is the IP address of the tftp server that contains the public key file
that you want to import into the device.

The filename variable is the name of the dsa public key file that you want to import into the device.

The remove parameter deletes the key from the system.

To display the currently loaded public keys, enter the following command.

Syntax: show ip client-pub-key [| begin expression | exclude expression | include expression]

To clear the public keys from the buffers, enter the following command.

Brocade# clear public-key

Syntax: clear public-key

Use the ip ssh pub-key remove command to delete the public key from the system.

Enabling DSA public key authentication

DSA public key authentication is enabled by default. You can disable or re-enable it manually.

To enable DSA public key authentication.

Brocade(config)# ip ssh key-authentication yes

To disable DSA public key authentication.

Brocade(config)# ip ssh key-authentication no

Syntax: ip ssh key-authentication yes | no

Brocade# show ip client-pub-key

---- BEGIN SSH2 PUBLIC KEY ----

Comment: DSA Public Key

AAAAB3NzaC1kc3MAAACBAPY8ZOHY2yFSJA6XYC9HRwNHxaehvx5wOJ0rzZdzoSOXxbET

W6ToHv8D1UJ/z+zHo9Fiko5XybZnDIaBDHtblQ+Yp7StxyltHnXF1YLfKD1G4T6JYrdH YI14Om

1eg9e4NnCRleaqoZPF3UGfZia6bXrGTQf3gJq2e7Yisk/gF+1VAAAAFQDb8D5cv

wHWTZDPfX0D2s9Rd7NBvQAAAIEAlN92+Bb7D4KLYk3IwRbXblwXdkPggA4pfdtW9v

GfJ0/RHd+NjB4eo1D+0dix6tXwYGN7PKS5R/FXPNwxHPapcj9uL1Jn2AWQ2dsknf+i/FAA

vioUPkmdMc0zuWoSOEsSNhVDtX3WdvVcGcBq9cetzrtOKWOocJmJ80qadxTRHtUAAACB

AN7CY+KKv1gHpRzFwdQm7HK9bb1LAo2KwaoXnadFgeptNBQeSXG1vO+JsvphVMBJc9HS

n24VYtYtsMu74qXviYjziVucWKjjKEb11juqnF0GDlB3VVmxHLmxnAz643WK42Z7dLM5

sY29ouezv4Xz2PuMch5VGPP+CDqzCM4loWgV

---- END SSH2 PUBLIC KEY ----