1-27
If a client does not support first-time authentication, it will refuse to access any unauthenticated server.
In this case, you need to configure the public key of the server on the client and associate the public key
and the server so that the client can authenticate the server during login.
If a pair of SSH peers are both switches that support both DSA and RSA, you must configure the DSA
public key of the server on the client.
Related command:
ssh client first-time enable
.
Examples
# Specify the name of the DSA public key of the server (whose IP address is 192.168.0.1) as
pub.ppk
on the client.
<Sysname>system-view
System View: return to User View with Ctrl+Z.
[Sysname] ssh client 192.168.0.1 assign publickey pub.ppk
ssh client first-time enable
Syntax
ssh client first-time enable
undo ssh client first-time
View
System view
Parameters
None
Description
Use the
ssh client first-time enable
command to enable the client to run first-time authentication for
the SSH server it accesses for the first time.
Use the
undo ssh client first-time
command to disable the client from running first-time
authentication.
By default, the client is enabled to run first-time authentication.
Note that:
z
With first-time authentication enabled, an SSH client that is not configured with the server’s host
public key can continue accessing the server when it accesses the server for the first time. The
SSH server sends its host public key to the client automatically, and the client saves the key for use
Summary of Contents for 5500-EI PWR
Page 43: ...2 6...
Page 76: ...1 17...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Page 519: ...iii...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Page 1111: ...ii xmodem get 3 18...
Page 1314: ...A 44 Z...