Configuring Secure Shell (SSH)

Further Information on SSH Client Public-Key Authentication

 

The babble option converts the key data to phonetic

 

hashes that are easier for visual comparisons.

 

The fingerprint option converts the key data to hexadec­

 

imal hashes that are for the same purpose.

 

The keylist-strselects keys to display (comma-delimited

 

list).

 

The manager option allows you to select manager public

 

keys

 

The operator option allows you to select operator public

 

keys.

 

 

N o t e

Beginning with software release K_12_XX or later, copy usb pub-key file can

 

also be used as a method for copying a public key file to the switch.

 

For example, if you wanted to copy a client public-key file named clientkeys.txt

 

 

from a TFTP server at 10.38.252.195 and then display the file contents:

Key Index Number

Figure 7-14. Example of Copying and Displaying a Client Public-Key File Containing Two Different Client Public Keys for the Same Client

Replacing or Clearing the Public Key File. The client public-key file remains in the switch’s flash memory even if you erase the startup-config file, reset the switch, or reboot the switch.

You can remove the existing client public-key file or specific keys by executing the clear crypto public-keycommand. This clears the public keys from both management modules. The module that is not active must be in standby mode.

7-27