309
Configuration guidelines
• If you configure a user interface to support SSH, be sure to configure the corresponding
authentication mode with the authentication-mode scheme command.
• For a user interface configured to support SSH, you cannot change the authentication mode. To
change the authentication mode, undo the SSH support configuration first.
Configuration procedure
To configure the protocols for a user interface to support:
Ste
Command
Remarks
1. Enter system view. system-view N/A
2. Enter user interface view of
one or more user interfaces.
user-interface vty number
[ ending-number ]
N/A
3. Set the login authentication
mode to scheme.
authentication-mode scheme
By default, the authentication
mode is password.
4. Configure the user interfaces
to support SSH login.
protocol inbound { all | ssh }
Optional.
All protocols are supported by
default.
For more information about the authentication-mode and protocol inbound commands, see
Fundamentals Command Reference.
Configuring a client's host public key
This configuration task is only necessary for SSH users using publickey authentication.
To allow an SSH user to pass publickey authentication and log in to the server, you must configure the
client's DSA, RSA, or ECDSA host public key on the server, and configure the client to use the
corresponding host private key, so that the server uses the digital signature to authenticate the client.
You can manually configure the public key of an SSH client on the server, or import it from the public key
file:
• Configure it manually—You can type or copy the public key to the SSH server. The public key must
have not been converted and be in the Distinguished Encoding Rules (DER) encoding format.
• Import it from the public key file—During the import process, the server will automatically convert
the public key in the public key file to a string in Public Key Cryptography Standards (PKCS) format,
and save it locally. Before importing the public key, you must upload the public key file (in binary)
to the server through FTP or TFTP.
NOTE:
HP recommends you to configure a client public key by importing it from a public key file.
For more information about client public key configuration, see "Managing public keys."
Configuring a client public key manually
Ste
Command
Remarks
1. Enter system view.
system-view N/A