Using Public Key Authentication For Ssh - Dell iDRAC7 User Manual

Table of Contents

Advertisement

Scheme Type
Message Integrity
Authentication
PKA Authentication

Using Public Key Authentication For SSH

iDRAC7 supports the Public Key Authentication (PKA) over SSH. This is a licensed feature. When the PKA over SSH is
set up and used correctly, you need not enter the user name or password while logging into iDRAC7. This is useful for
setting up automated scripts that perform various functions. The uploaded keys must be in RFC 4716 or openssh format.
Else, you must convert the keys into that format.
In any scenario, a pair of private and public key must be generated on the management station. The public key is
uploaded to iDRAC7 local user and private key is used by the SSH client to establish the trust relationship between the
management station and iDRAC7.
You can generate the public or private key pair using:
PuTTY Key Generator application for clients running Windows
ssh-keygen CLI for clients running Linux.
CAUTION: This privilege is normally reserved for users who are members of the Administrator user group on
iDRAC7. However, users in the 'Custom' user group can be assigned this privilege. A user with this privilege can
modify any user's configuration. This includes creation or deletion of any user, SSH Key management for users,
and so on. For these reasons, assign this privilege carefully.
CAUTION: The capability to upload, view, and/ or delete SSH keys is based on the 'Configure Users' user privilege.
This privilege allows user(s) to configure another user's SSH key. You should grant this privilege carefully.
Generating Public Keys for Windows
PuTTY Key Generator application to create the basic key:
To use the
1.
Start the application and select either SSH-2 RSA or SSH-2 DSA for the type of key to generate. (SSH-1 is not
supported). The supported key generation algorithms are RSA and DSA only.
2.
Enter the number of bits for the key. For RSA, it is between 768 and 4096 bits and for DSA, it 1024 bits.
3.
Click Generate and move the mouse in the window as directed.
The keys are generated.
4.
You can modify the key comment field.
118
Scheme
RIJNDAEL256-CBC
AES192-CBC
RIJNDAEL192-CBC
AES128-CBC
RIJNDAEL128-CBC
BLOWFISH-128-CBC
3DES-192-CBC
ARCFOUR-128
HMAC-SHA1-160
HMAC-SHA1-96
HMAC-MD5-128
HMAC-MD5-96
Password
Public-private key pairs

Advertisement

Table of Contents
loading

Table of Contents