CHAPTER 47
X.509v3 Certificates for SSH Authentication
The X.509v3 Certificates for SSH Authentication feature uses public key algorithm (PKI) for server and
user authentication, and allows the Secure Shell (SSH) protocol to verify the identity of the owner of a key
pair via digital certificates, signed and issued by a Certificate Authority (CA).
This module describes how to configure server and user certificate profiles for a digital certificate.
•
Finding Feature Information, page 1117
•
Prerequisites for X.509v3 Certificates for SSH Authentication, page 1117
•
Restrictions for X.509v3 Certificates for SSH Authentication, page 1118
•
Information About X.509v3 Certificates for SSH Authentication, page 1118
•
How to Configure X.509v3 Certificates for SSH Authentication, page 1119
•
Verifying the Server and User Authentication Using Digital Certificates , page 1122
•
Configuration Examples for X.509v3 Certificates for SSH Authentication, page 1123
•
Additional References for X.509v3 Certificates for SSH Authentication, page 1124
•
Feature Information for X.509v3 Certificates for SSH Authentication, page 1124
Finding Feature Information
Your software release may not support all the features documented in this module. For the latest caveats and
feature information, see Bug Search Tool and the release notes for your platform and software release. To
find information about the features documented in this module, and to see a list of the releases in which each
feature is supported, see the feature information table at the end of this module.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support.
To access Cisco Feature Navigator, go to http://www.cisco.com/go/cfn. An account on Cisco.com is not
required.
Prerequisites for X.509v3 Certificates for SSH Authentication
The X.509v3 Certificates for SSH Authentication feature replaces the ip ssh server authenticate user
command with the ip ssh server algorithm authentication command. Configure the default ip ssh server
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1117