1847052 Members
5068 Online
110261 Solutions
New Discussion

Re: ssh

 
khilari
Regular Advisor

ssh

Hi people, well i wanted to know as to how do u configure ssh on your local hp-ux system.And secondly, how have your experience have been as one using it over traditional telnet. Lastly, does sftp work on the same rules as ssh.
Thanks
6 REPLIES 6
IT_2007
Honored Contributor

Re: ssh

Install ssh product from HP portal site and then look at /etc/sshd/sshd_config file to configure. Usually, root is not allowed to login remotely other than console. Otherwise standard configuratin should work to login by users.

scp is a subsystem on sshd_config. It works same as ssh. This is a secure file transfers.

Once you install and config ssh then you can disable telnet and ftp services.

Yogeeraj_1
Honored Contributor

Re: ssh

hi,

attached one great document that i use as reference: Using H/P's Secure Shell & Secure Copy by chris vail


hope this helps!

kind regards
yogeeraj
No person was ever honoured for what he received. Honour has been the reward for what he gave (clavin coolidge)
Yogeeraj_1
Honored Contributor

Re: ssh

hi,

attached one great document that i use as reference: Using H/P's Secure Shell & Secure Copy by chris vail


hope this helps!

kind regards
yogeeraj
No person was ever honoured for what he received. Honour has been the reward for what he gave (clavin coolidge)
Ralph Grothe
Honored Contributor

Re: ssh

Use the official HP-UX port of OpenSSH, which HP call "Secure Shell"

# swlist|grep -Ei secure.?shell
T1471AA A.03.61.002 HP-UX Secure Shell

You can download it for free from software.hp.com (fill in the search input field to find the exact URL),
but you will also find it on HPs' Application CDs.
Installation is as easy as the usual swinstall.
Installation scripts of the depot will automatically produce host keys.
The basic configuration file, which you find after installation in /opt/ssh/etc/sshd_config
requires little to no adaptation.
The depot also installs init script with rc.config.d file, and sets symlinks.
Thus, you merely need to run "/sbin/init.d/secsh start",
if some postinstall procedure hasn't done so already.

Yes, ssh is a much better replacement for telnet and the r* commands.
HP have patched most of their relevant products that formerly required r* commands in trusted hosts environments (like ServiceGuard or bootsys from Ignite) to tolerate SSH RSA key authorized logins.
Thus, you will hardly need the old commands anymore.
Madness, thy name is system administration
Ralph Grothe
Honored Contributor

Re: ssh

Forgot, the manpages that the Secure Shell accompny are an excellent reference (and usually the only one I mostly need).
Especially the man sshd_config explains all possible settings.
Madness, thy name is system administration
Steven E. Protter
Exalted Contributor

Re: ssh

Shalom,

I agree the sshd_config file is one of the better english language documentation configuration files around.

Picking your ssh/secure shell release is important. Recent releases have had some rather rough security problems and fuctionality bugs.

http://software.hp.com

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com