- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- ssh on 5304xl switch
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-09-2005 07:29 PM
тАО11-09-2005 07:29 PM
I need to enable client key authentification only, so I configure: HP ProCurve Switch 5304XL(config)#aaa authentication ssh login public-key none.
However, if I don't provide my key I can still get access to the switch through SSH by entering manager's password. That configuration works fine on my HP Procurve 2524, but not on 5304xl
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-12-2005 01:55 AM
тАО11-12-2005 01:55 AM
SolutionYou also logged the case via EMEA Support Center right? 1208976505
I am currently working on the issue and get back to you on Monday. I could reproduce the behavior you were seeing on the 5304 but not with all SSH Clients. When using SecureCRT from vandycke (www.vandycke.com) version 4.0.7 all worked as expected. So no key specified means no access. When using Putty Verion 0.58 I was granted access by specifying Username/Password.
I will keep you posted.
Regards, Ardon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-13-2005 05:49 PM
тАО11-13-2005 05:49 PM
Re: ssh on 5304xl switch
Thanks for your reply and waiting for further news.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-28-2005 05:57 AM
тАО11-28-2005 05:57 AM
Re: ssh on 5304xl switch
1) generate the switches pub/private key
# crypto key generate ssh rsa
# sh crypto host-public-key
2) generate client public/private key pairs
3) enable ssh on switch
# ip ssh
4) copy client public keys to switch
5300# copy tftp public-key-file 15.55.24.52 hpux.pub manager append
5300# copy tftp public-key-file 15.55.24.52 linux.pub manager append
5300# copy tftp public-key-file 15.55.24.52 putty.pub manager append
# sh crypto client-public-key manager
5) get switches public key on clients
client learns key on first connect, or
copy/paste key from display into known_hosts file on client
6) configure the switch for client public-key ssh auth only.
5300# aaa auth ssh login public-key none
5300# aaa auth ssh enable public-key none
Let me know if this works for you...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-28-2005 10:34 PM
тАО11-28-2005 10:34 PM
Re: ssh on 5304xl switch
5300# aaa auth ssh login public-key none
5300# aaa auth ssh enable public-key none
then I cannot access manager level:
HP ProCurve Switch 5304XL> enable
HP ProCurve Switch 5304XL>
The switch does not prompt me for user and passw
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-23-2005 06:19 AM
тАО12-23-2005 06:19 AM
Re: ssh on 5304xl switch
5300# copy tftp public-key-file 15.55.24.52 hpux.pub manager append
^^^^^^^
note the "manager" key word
.
.
To see if the keys made it to the manager public-key file, use this command:
5300# sh crypto client-public-key manager
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-11-2006 05:56 PM
тАО01-11-2006 05:56 PM
Re: ssh on 5304xl switch
The documentation for the 5304 switches is not correct, there is no word that public keys must be also loaded to manager file and 'aaa auth ssh enable public none' must be added to achieve desired restriction to login only clients having correct key.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-11-2006 06:00 PM
тАО01-11-2006 06:00 PM