- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- 2848 key-authenticated ssh access to manager mode
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-11-2008 01:44 AM
тАО10-11-2008 01:44 AM
2848 key-authenticated ssh access to manager mode
I have two (I think) identically configured switches, one in the lab and one productive box.
# show version
Image stamp: /sw/code/build/mako(mkfs)
Aug 15 2007 13:53:51
I.10.43
105
Boot Image: Primary
#
2848 scysw00503# show ip ssh
SSH Enabled : Yes
SSH Version : 2
TCP Port Number : 22
Timeout (sec) : 120
Server Key Size (bits) : 1024
Secure Copy Enabled : No
Ses Type | Protocol Source IP and Port
--- -------- + --------- ---------------------
1 console |
2 telnet |
3 inactive |
4 telnet |
# show authentication
Status and Counters - Authentication Information
Login Attempts : 3
Respect Privilege : Disabled
| Login Login Enable Enable
Access Task | Primary Secondary Primary Secondary
----------- + ---------- ---------- ---------- ----------
Console | Local None Local None
Telnet | Local None Local None
Port-Access | Local None
Webui | Local None Local None
SSH | PublicKey None PublicKey None
Web-Auth | ChapRadius None
MAC-Auth | ChapRadius None
# show crypto client-public-key
Manager keys:
0,mh@scyw00225 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA188zafsfW7wT7Vg/OGH/bNk5snqWK
zLfDLszlj+5RVbpQt9KxkWyGGnLvY4vgt9vNRyVcYu6FQrbM1tNvBdp+ZebNyyVMq/uK/bKz+KFj+I3+
eTGUvI8tUbtcHJp7DRqYxmLWg3hIPEg+UMUCm0K9kDlfi7X5yybnrU0uvBe8kCMCyzs0LSVGvX1RHukD
zy8ZgW4mCU25vAvgZu9nS8XYTo1xnqBPPQdH2wpFFR/p8Up00ZGfmcnzfo2lBh2+puGe8N6067la/6Jd
Lx9MPTkCxwphDFTjdC045N1veK5MxPgKpwsOK7nc9RNCAqFkECObQP03MVCX0eHq96SabbqDQ==
# show crypto host-public-key
SSH host public key file
Version 1 format:
896 35 3830371328877558150264723662879452352090459838062476281144136373461359260
99402738826414267181525559146224627944485827044920066816174950513516199838216615
33196644357337434658201223266115444895517842429782919785151577820155519074434236
7009253048249588729764165228881724729
Version 2 format:
ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAHEAuZyHANPWp59s2P47pfU4TTD61fB0+dQBpF50XcJ2eT0v
lggPBoo9dCbROJTKhWlzLVhloAhSF5fFuHFtusSZZldBgy3xSnyzTX6cb9XNZFJQNmuhr4EWqpthwbwB
6OzoQCDolWO5k4DHpe2ldXdFOQ==
#
Both switches have the IP address from where I am sshing in listed in their "ip authorized-managers" list with Access-Level Manager. Both switches have an operator and an manager password set.
When I ssh in to the lab switch with
ssh manager@
However, when I ssh in to the productive switch with ssh manager@
Where can the both switches' configuration differ that doesn't allow me to get manager access on the productive switch when coming in via ssh?
Any hints will be appreciated.
Greetings
Marc
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-12-2008 11:02 PM
тАО10-12-2008 11:02 PM
Re: 2848 key-authenticated ssh access to manager mode
show authentication
SSH | PublicKey None PublicKey None
Was this output from lab switch or production?
This is correct config.
Second:
# show crypto client-public-key
there must be only manager keys, if you loaded same key to operator storage, you will get only 'login' level and it is not possible to switch to 'enable' level.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 01:20 AM
тАО10-13-2008 01:20 AM
Re: 2848 key-authenticated ssh access to manager mode
you wrote:
> I had similar problem, there are two
> things to check:
> show authentication
> SSH | PublicKey None PublicKey None
> Was this output from lab switch or
> production?
Both Lab switches and Production switches give exactly the same output.
> This is correct config.
> Second:
> # show crypto client-public-key
> there must be only manager keys, if you
> loaded same key to operator storage, you
> will get only 'login' level and it is not
> possible to switch to 'enable' level.
Both Lab switches and Production switches only have manager keys, complete output of "show crypto client-public-key" on both Lab and Production is given above.
Any more ideas?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:09 AM
тАО10-13-2008 02:09 AM
Re: 2848 key-authenticated ssh access to manager mode
Both switches 28 series?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:18 AM
тАО10-13-2008 02:18 AM
Re: 2848 key-authenticated ssh access to manager mode
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:23 AM
тАО10-13-2008 02:23 AM
Re: 2848 key-authenticated ssh access to manager mode
Can you show running config of production sw.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:41 AM
тАО10-13-2008 02:41 AM
Re: 2848 key-authenticated ssh access to manager mode
Running config of the productive switch:
hostname "2848 sw00512"
snmp-server contact "me@example.com"
snmp-server location "foo"
max-vlans 256
time daylight-time-rule Middle-Europe-and-Portugal
console inactivity-timer 30
no web-management
interface 39
qos priority 6
exit
interface 40
qos priority 6
exit
interface 41
qos priority 6
exit
interface 42
qos priority 6
exit
ip default-gateway 10.2.100.94
sntp server 10.2.100.62
timesync sntp
sntp unicast
logging facility local0
logging 172.16.248.33
snmp-server community "
vlan 1
name "default"
no ip address
no untagged 1-48
exit
vlan 100
name "100mgtA"
untagged 43-48
ip address 10.2.100.77 255.255.255.224
exit
vlan 101
name "101Test"
no ip address
tagged 43-48
exit
vlan 103
name "103extConn"
no ip address
tagged 43-48
exit
vlan 104
name "104mhMisc"
no ip address
tagged 43-48
exit
vlan 108
name "108OffCli"
untagged 1,5-6,10-11,14-16,20,22,26,28,32
no ip address
tagged 43-48
exit
vlan 110
name "110TKAnlage"
untagged 39-42
no ip address
tagged 43-48
exit
vlan 120
name "120OffSrv"
untagged 2-4,7-9,12-13,17-19,21,23-25,27,29-31,33-38
no ip address
tagged 43-48
exit
ip authorized-managers 10.1.2.0 255.255.255.0
ip authorized-managers 10.2.100.94
ip authorized-managers 172.16.248.33 access Operator
ip authorized-managers 10.1.108.0 255.255.254.0
aaa authentication ssh login public-key
aaa authentication ssh enable public-key
spanning-tree
spanning-tree protocol-version MSTP
spanning-tree config-name "dotqa-office"
spanning-tree config-revision 8101
spanning-tree instance 2 vlan 101 103 104 108 110 120
ip ssh
ip ssh key-size 1024
password manager
password operator
2848 scysw00512#
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:42 AM
тАО10-13-2008 02:42 AM
Re: 2848 key-authenticated ssh access to manager mode
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 02:48 AM
тАО10-13-2008 02:48 AM
Re: 2848 key-authenticated ssh access to manager mode
sh crypto client-public-key operator
If you get response:
Client public key file corrupt or not found.
Then it's ok.
Your config looks good, no clues.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 04:08 AM
тАО10-13-2008 04:08 AM
Re: 2848 key-authenticated ssh access to manager mode
generate new ssh key and upload it to operator storage:
copy tftp pub-key-file
Now test connection with old key and new one, should be different levels granted on access.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-14-2008 03:05 AM
тАО10-14-2008 03:05 AM
Re: 2848 key-authenticated ssh access to manager mode
you wrote:
>I am not sure if 'show crypto client-public-key' also displays operator keys,
It does:
|2848 sw00503# show crypto client-public-key
|Manager keys:
|0,mh ssh-rsa
|Operator keys:
|0,mhtest ssh-rsa
|2848 sw00503#
>you can test this way:
>generate new ssh key and upload it to operator storage:
>copy tftp pub-key-file
>Now test connection with old key and new one, should be different levels granted on access.
Unfortunately, both keys only grant operator access.
Greetings
Marc