<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2848 key-authenticated ssh access to manager mode in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285084#M16069</link>
    <description>&lt;!--!*#--&gt;My ssh client is OpenSSH 5.1p1.&lt;BR /&gt;&lt;BR /&gt;Running config of the productive switch:&lt;BR /&gt;hostname "2848 sw00512"&lt;BR /&gt;snmp-server contact "me@example.com"&lt;BR /&gt;snmp-server location "foo"&lt;BR /&gt;max-vlans 256&lt;BR /&gt;time daylight-time-rule Middle-Europe-and-Portugal&lt;BR /&gt;console inactivity-timer 30&lt;BR /&gt;no web-management&lt;BR /&gt;interface 39&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 40&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 41&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 42&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;ip default-gateway 10.2.100.94&lt;BR /&gt;sntp server 10.2.100.62&lt;BR /&gt;timesync sntp&lt;BR /&gt;sntp unicast&lt;BR /&gt;logging facility local0&lt;BR /&gt;logging 172.16.248.33&lt;BR /&gt;snmp-server community "&lt;SNIP&gt;" Operator&lt;BR /&gt;vlan 1&lt;BR /&gt;   name "default"&lt;BR /&gt;   no ip address&lt;BR /&gt;   no untagged 1-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 100&lt;BR /&gt;   name "100mgtA"&lt;BR /&gt;   untagged 43-48&lt;BR /&gt;   ip address 10.2.100.77 255.255.255.224&lt;BR /&gt;   exit&lt;BR /&gt;vlan 101&lt;BR /&gt;   name "101Test"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 103&lt;BR /&gt;   name "103extConn"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 104&lt;BR /&gt;   name "104mhMisc"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 108&lt;BR /&gt;   name "108OffCli"&lt;BR /&gt;   untagged 1,5-6,10-11,14-16,20,22,26,28,32&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 110&lt;BR /&gt;   name "110TKAnlage"&lt;BR /&gt;   untagged 39-42&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 120&lt;BR /&gt;   name "120OffSrv"&lt;BR /&gt;   untagged 2-4,7-9,12-13,17-19,21,23-25,27,29-31,33-38&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;ip authorized-managers 10.1.2.0 255.255.255.0&lt;BR /&gt;ip authorized-managers 10.2.100.94&lt;BR /&gt;ip authorized-managers 172.16.248.33 access Operator&lt;BR /&gt;ip authorized-managers 10.1.108.0 255.255.254.0&lt;BR /&gt;aaa authentication ssh login public-key&lt;BR /&gt;aaa authentication ssh enable public-key&lt;BR /&gt;spanning-tree&lt;BR /&gt;spanning-tree protocol-version MSTP&lt;BR /&gt;spanning-tree config-name "dotqa-office"&lt;BR /&gt;spanning-tree config-revision 8101&lt;BR /&gt;spanning-tree instance 2 vlan 101 103 104 108 110 120&lt;BR /&gt;ip ssh&lt;BR /&gt;ip ssh key-size 1024&lt;BR /&gt;password manager&lt;BR /&gt;password operator&lt;BR /&gt;&lt;BR /&gt;2848 scysw00512# &lt;BR /&gt;&lt;/SNIP&gt;</description>
    <pubDate>Mon, 13 Oct 2008 09:41:08 GMT</pubDate>
    <dc:creator>Marc Haber</dc:creator>
    <dc:date>2008-10-13T09:41:08Z</dc:date>
    <item>
      <title>2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285078#M16063</link>
      <description>&lt;!--!*#--&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;I have two (I think) identically configured switches, one in the lab and one productive box. &lt;BR /&gt;&lt;BR /&gt;# show version&lt;BR /&gt;Image stamp:    /sw/code/build/mako(mkfs)&lt;BR /&gt;                Aug 15 2007 13:53:51&lt;BR /&gt;                I.10.43&lt;BR /&gt;                105&lt;BR /&gt;Boot Image:     Primary&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;2848 scysw00503# show ip ssh&lt;BR /&gt;&lt;BR /&gt;  SSH Enabled            : Yes&lt;BR /&gt;  SSH Version            : 2&lt;BR /&gt;  TCP Port Number        : 22&lt;BR /&gt;  Timeout (sec)          : 120&lt;BR /&gt;  Server Key Size (bits) : 1024&lt;BR /&gt;  Secure Copy Enabled    : No&lt;BR /&gt;&lt;BR /&gt;  Ses Type     | Protocol  Source IP and Port&lt;BR /&gt;  --- -------- + --------- ---------------------&lt;BR /&gt;  1   console  |&lt;BR /&gt;  2   telnet   |&lt;BR /&gt;  3   inactive |&lt;BR /&gt;  4   telnet   |&lt;BR /&gt;&lt;BR /&gt;# show authentication&lt;BR /&gt;&lt;BR /&gt; Status and Counters - Authentication Information&lt;BR /&gt;&lt;BR /&gt;  Login Attempts : 3&lt;BR /&gt;  Respect Privilege : Disabled&lt;BR /&gt;&lt;BR /&gt;              | Login      Login      Enable     Enable&lt;BR /&gt;  Access Task | Primary    Secondary  Primary    Secondary&lt;BR /&gt;  ----------- + ---------- ---------- ---------- ----------&lt;BR /&gt;  Console     | Local      None       Local      None&lt;BR /&gt;  Telnet      | Local      None       Local      None&lt;BR /&gt;  Port-Access | Local      None&lt;BR /&gt;  Webui       | Local      None       Local      None&lt;BR /&gt;  SSH         | PublicKey  None       PublicKey  None&lt;BR /&gt;  Web-Auth    | ChapRadius None&lt;BR /&gt;  MAC-Auth    | ChapRadius None&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# show crypto client-public-key&lt;BR /&gt;&lt;BR /&gt;Manager keys:&lt;BR /&gt;&lt;BR /&gt;0,mh@scyw00225 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA188zafsfW7wT7Vg/OGH/bNk5snqWK&lt;BR /&gt;zLfDLszlj+5RVbpQt9KxkWyGGnLvY4vgt9vNRyVcYu6FQrbM1tNvBdp+ZebNyyVMq/uK/bKz+KFj+I3+&lt;BR /&gt;eTGUvI8tUbtcHJp7DRqYxmLWg3hIPEg+UMUCm0K9kDlfi7X5yybnrU0uvBe8kCMCyzs0LSVGvX1RHukD&lt;BR /&gt;zy8ZgW4mCU25vAvgZu9nS8XYTo1xnqBPPQdH2wpFFR/p8Up00ZGfmcnzfo2lBh2+puGe8N6067la/6Jd&lt;BR /&gt;Lx9MPTkCxwphDFTjdC045N1veK5MxPgKpwsOK7nc9RNCAqFkECObQP03MVCX0eHq96SabbqDQ==&lt;BR /&gt;&lt;BR /&gt;# show crypto host-public-key&lt;BR /&gt;&lt;BR /&gt;SSH host public key file&lt;BR /&gt;Version 1 format:&lt;BR /&gt;&lt;BR /&gt;896 35 3830371328877558150264723662879452352090459838062476281144136373461359260&lt;BR /&gt;99402738826414267181525559146224627944485827044920066816174950513516199838216615&lt;BR /&gt;33196644357337434658201223266115444895517842429782919785151577820155519074434236&lt;BR /&gt;7009253048249588729764165228881724729&lt;BR /&gt;&lt;BR /&gt;Version 2 format:&lt;BR /&gt;&lt;BR /&gt;ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAHEAuZyHANPWp59s2P47pfU4TTD61fB0+dQBpF50XcJ2eT0v&lt;BR /&gt;lggPBoo9dCbROJTKhWlzLVhloAhSF5fFuHFtusSZZldBgy3xSnyzTX6cb9XNZFJQNmuhr4EWqpthwbwB&lt;BR /&gt;6OzoQCDolWO5k4DHpe2ldXdFOQ==&lt;BR /&gt;&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;Both switches have the IP address from where I am sshing in listed in their "ip authorized-managers" list with Access-Level Manager. Both switches have an operator and an manager password set.&lt;BR /&gt;&lt;BR /&gt;When I ssh in to the lab switch with &lt;BR /&gt;ssh manager@&lt;IP-ADDRESS&gt;, I get a "sw12#" prompt with manager access without being asked for the password. That is the desired behavior.&lt;BR /&gt;&lt;BR /&gt;However, when I ssh in to the productive switch with ssh manager@&lt;HOST-NAME&gt;, I only get an operator-level "switch&amp;gt;" prompt, and the enable command is replied with "Access denied".&lt;BR /&gt;&lt;BR /&gt;Where can the both switches' configuration differ that doesn't allow me to get manager access on the productive switch when coming in via ssh?&lt;BR /&gt;&lt;BR /&gt;Any hints will be appreciated.&lt;BR /&gt;&lt;BR /&gt;Greetings&lt;BR /&gt;Marc&lt;BR /&gt;&lt;/HOST-NAME&gt;&lt;/IP-ADDRESS&gt;</description>
      <pubDate>Sat, 11 Oct 2008 08:44:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285078#M16063</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-11T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285079#M16064</link>
      <description>I had similar problem, there are two things to check:&lt;BR /&gt;show authentication&lt;BR /&gt;SSH         | PublicKey  None       PublicKey  None&lt;BR /&gt;Was this output from lab switch or production?&lt;BR /&gt;This is correct config.&lt;BR /&gt;Second:&lt;BR /&gt;# show crypto client-public-key&lt;BR /&gt;there  must be only manager keys, if you loaded same key to operator storage, you will get only 'login' level and it is not possible to switch to 'enable' level.</description>
      <pubDate>Mon, 13 Oct 2008 06:02:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285079#M16064</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-13T06:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285080#M16065</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;you wrote:&lt;BR /&gt;&amp;gt; I had similar problem, there are two&lt;BR /&gt;&amp;gt; things to check:&lt;BR /&gt;&amp;gt; show authentication&lt;BR /&gt;&amp;gt; SSH | PublicKey None PublicKey None&lt;BR /&gt;&amp;gt; Was this output from lab switch or&lt;BR /&gt;&amp;gt; production?&lt;BR /&gt;&lt;BR /&gt;Both Lab switches and Production switches give exactly the same output.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; This is correct config.&lt;BR /&gt;&amp;gt; Second:&lt;BR /&gt;&amp;gt; # show crypto client-public-key&lt;BR /&gt;&amp;gt; there must be only manager keys, if you&lt;BR /&gt;&amp;gt; loaded same key to operator storage, you&lt;BR /&gt;&amp;gt; will get only 'login' level and it is not&lt;BR /&gt;&amp;gt; possible to switch to 'enable' level. &lt;BR /&gt;&lt;BR /&gt;Both Lab switches and Production switches only have manager keys, complete output of "show crypto client-public-key" on both Lab and Production is given above.&lt;BR /&gt;&lt;BR /&gt;Any more ideas?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Oct 2008 08:20:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285080#M16065</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-13T08:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285081#M16066</link>
      <description>firmware version the same?&lt;BR /&gt;Both switches 28 series?</description>
      <pubDate>Mon, 13 Oct 2008 09:09:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285081#M16066</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-13T09:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285082#M16067</link>
      <description>Switches are identical, 2848 with firmware I.10.43&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Oct 2008 09:18:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285082#M16067</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-13T09:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285083#M16068</link>
      <description>what ssh client are you using, putty?&lt;BR /&gt;Can you show running config of production sw.</description>
      <pubDate>Mon, 13 Oct 2008 09:23:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285083#M16068</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-13T09:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285084#M16069</link>
      <description>&lt;!--!*#--&gt;My ssh client is OpenSSH 5.1p1.&lt;BR /&gt;&lt;BR /&gt;Running config of the productive switch:&lt;BR /&gt;hostname "2848 sw00512"&lt;BR /&gt;snmp-server contact "me@example.com"&lt;BR /&gt;snmp-server location "foo"&lt;BR /&gt;max-vlans 256&lt;BR /&gt;time daylight-time-rule Middle-Europe-and-Portugal&lt;BR /&gt;console inactivity-timer 30&lt;BR /&gt;no web-management&lt;BR /&gt;interface 39&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 40&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 41&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;interface 42&lt;BR /&gt;   qos priority 6&lt;BR /&gt;exit&lt;BR /&gt;ip default-gateway 10.2.100.94&lt;BR /&gt;sntp server 10.2.100.62&lt;BR /&gt;timesync sntp&lt;BR /&gt;sntp unicast&lt;BR /&gt;logging facility local0&lt;BR /&gt;logging 172.16.248.33&lt;BR /&gt;snmp-server community "&lt;SNIP&gt;" Operator&lt;BR /&gt;vlan 1&lt;BR /&gt;   name "default"&lt;BR /&gt;   no ip address&lt;BR /&gt;   no untagged 1-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 100&lt;BR /&gt;   name "100mgtA"&lt;BR /&gt;   untagged 43-48&lt;BR /&gt;   ip address 10.2.100.77 255.255.255.224&lt;BR /&gt;   exit&lt;BR /&gt;vlan 101&lt;BR /&gt;   name "101Test"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 103&lt;BR /&gt;   name "103extConn"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 104&lt;BR /&gt;   name "104mhMisc"&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 108&lt;BR /&gt;   name "108OffCli"&lt;BR /&gt;   untagged 1,5-6,10-11,14-16,20,22,26,28,32&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 110&lt;BR /&gt;   name "110TKAnlage"&lt;BR /&gt;   untagged 39-42&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 120&lt;BR /&gt;   name "120OffSrv"&lt;BR /&gt;   untagged 2-4,7-9,12-13,17-19,21,23-25,27,29-31,33-38&lt;BR /&gt;   no ip address&lt;BR /&gt;   tagged 43-48&lt;BR /&gt;   exit&lt;BR /&gt;ip authorized-managers 10.1.2.0 255.255.255.0&lt;BR /&gt;ip authorized-managers 10.2.100.94&lt;BR /&gt;ip authorized-managers 172.16.248.33 access Operator&lt;BR /&gt;ip authorized-managers 10.1.108.0 255.255.254.0&lt;BR /&gt;aaa authentication ssh login public-key&lt;BR /&gt;aaa authentication ssh enable public-key&lt;BR /&gt;spanning-tree&lt;BR /&gt;spanning-tree protocol-version MSTP&lt;BR /&gt;spanning-tree config-name "dotqa-office"&lt;BR /&gt;spanning-tree config-revision 8101&lt;BR /&gt;spanning-tree instance 2 vlan 101 103 104 108 110 120&lt;BR /&gt;ip ssh&lt;BR /&gt;ip ssh key-size 1024&lt;BR /&gt;password manager&lt;BR /&gt;password operator&lt;BR /&gt;&lt;BR /&gt;2848 scysw00512# &lt;BR /&gt;&lt;/SNIP&gt;</description>
      <pubDate>Mon, 13 Oct 2008 09:41:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285084#M16069</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-13T09:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285085#M16070</link>
      <description>My client address is 10.1.108.92, so it falls into a range that is allowed for manager access.&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Oct 2008 09:42:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285085#M16070</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-13T09:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285086#M16071</link>
      <description>I am not sure if 'show crypto client-public-key' also displays operator keys, try:&lt;BR /&gt;sh crypto client-public-key operator&lt;BR /&gt;If you get response:&lt;BR /&gt;Client public key file corrupt or not found.&lt;BR /&gt;Then it's ok.&lt;BR /&gt;Your config looks good, no clues.&lt;BR /&gt;</description>
      <pubDate>Mon, 13 Oct 2008 09:48:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285086#M16071</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-13T09:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285087#M16072</link>
      <description>you can test this way:&lt;BR /&gt;generate new ssh key and upload it to operator storage:&lt;BR /&gt;copy tftp pub-key-file &lt;IP-ADDR&gt; &lt;FILENAME&gt; operator append&lt;BR /&gt;Now test connection with old key and new one, should be different levels granted on access.&lt;/FILENAME&gt;&lt;/IP-ADDR&gt;</description>
      <pubDate>Mon, 13 Oct 2008 11:08:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285087#M16072</guid>
      <dc:creator>Igoris_1</dc:creator>
      <dc:date>2008-10-13T11:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: 2848 key-authenticated ssh access to manager mode</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285088#M16073</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;you wrote:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;I am not sure if 'show crypto client-public-key' also displays operator keys,&lt;BR /&gt;&lt;BR /&gt;It does:&lt;BR /&gt;&lt;BR /&gt;|2848 sw00503# show crypto client-public-key&lt;BR /&gt;|Manager keys:&lt;BR /&gt;|0,mh ssh-rsa &lt;SNIP&gt;&lt;BR /&gt;|Operator keys:&lt;BR /&gt;|0,mhtest ssh-rsa &lt;SNIP&gt;&lt;BR /&gt;|2848 sw00503#&lt;BR /&gt;&lt;BR /&gt;&amp;gt;you can test this way:&lt;BR /&gt;&amp;gt;generate new ssh key and upload it to operator storage:&lt;BR /&gt;&amp;gt;copy tftp pub-key-file &lt;IP-ADDR&gt; &lt;FILENAME&gt; operator append&lt;BR /&gt;&amp;gt;Now test connection with old key and new one, should be different levels granted on access. &lt;BR /&gt;&lt;BR /&gt;Unfortunately, both keys only grant operator access.&lt;BR /&gt;&lt;BR /&gt;Greetings&lt;BR /&gt;Marc&lt;BR /&gt;&lt;BR /&gt;&lt;/FILENAME&gt;&lt;/IP-ADDR&gt;&lt;/SNIP&gt;&lt;/SNIP&gt;</description>
      <pubDate>Tue, 14 Oct 2008 10:05:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/2848-key-authenticated-ssh-access-to-manager-mode/m-p/4285088#M16073</guid>
      <dc:creator>Marc Haber</dc:creator>
      <dc:date>2008-10-14T10:05:40Z</dc:date>
    </item>
  </channel>
</rss>

