Cisco 500 series Administration Manual page 349

Stackable managed switch
Hide thumbs Also See for 500 series:
Table of Contents

Advertisement

Using the SSH Client Feature
Protection Methods
Cisco 500 Series Stackable Managed Switch Administration Guide
Data can be encrypted using a one-time symmetric key negotiated during the
session.
Each switch being managed must have its own username/password, although the
same username/password can be used for multiple switches.
The password method is the default method on the switch.
Public/Private Keys
To use the public/private key method, create a username and public key on the
SSH server. The public key is generated on the switch, as described below, and
then copied to the server. The actions of creating a username on the server and
copying the public key to the server are not described in this guide.
RSA and DSA default key pairs are generated for the switch when it is booted.
One of these keys is used to encrypt the data being downloaded from the SSH
server. The RSA key is used by default.
If the user deletes one or both of these keys, they are regenerated.
The public/private keys are encrypted and stored in the device memory. The keys
are part of the device configuration file, and the private key can be displayed to
the user, in encrypted or plaintext form.
Since the private key cannot be copied directly to the private key of another
switch, an import method exists that enables copying private keys from switch to
switch (described in
Import Keys
In the key method, individual public/private keys must be created for each
individual switch, and these private keys cannot be copied directly from one
switch to another because of security considerations.
If there are multiple switches in the network, the process of creating public/private
keys for all the switches might be time-consuming, because each public/private
key must be created and then loaded onto the SSH server.
To facilitate this process, an additional feature enables secure transfer of the
encrypted private key to all switches in the system.
When a private key is created on a switch, it is also possible to create an
associated passphrase. This passphrase is used to encrypt the private key and to
import it into the remaining switches. In this way, all the switches can use the same
public/private key.
Import
Keys).
19
349

Advertisement

Table of Contents
loading

Table of Contents