ip ssh host-key-method

Enables or disables one or more secure host key algorithms.
Syntax
ip ssh host-key-method { ecdsa-sha2-nistp256 | ecdsa-sha2-nistp384 | ecdsa-sha2-nistp521 | rsa-sha2-512 | rsa-sha2-256 | ssh-rsa | ssh-ed25519 }
no ip ssh host-key-method { ecdsa-sha2-nistp256 | ecdsa-sha2-nistp384 | ecdsa-sha2-nistp521 | rsa-sha2-512 | rsa-sha2-256 | ssh-rsa | ssh-ed25519 }
Command Default

By default, all methods are supported but do not show up in the running-configuration unless explicitly configured.

Parameters
ecdsa-sha2-nistp256
Enables Elliptic Curve Digital Signature Algorithm Secure Hash Algorithm 2 NIST-P 256 as a secure host algorithm on the ICX device.
ecdsa-sha2-nistp384
Enables Elliptic Curve Digital Signature Algorithm Secure Hash Algorithm 2 NIST-P 384 as a secure host algorithm on the ICX device.
ecdsa-sha2-nistp512
Enables Elliptic Curve Digital Signature Algorithm Secure Hash Algorithm 2 NIST-P 512 as a secure host algorithm on the ICX device.
rsa-sha2-256
Enables Rivest Shamir Adleman Secure Hash Algorithm 2 256-bit as a secure host algorithm on the ICX device.
rsa-sha2-521
Enables Rivest Shamir Adleman Secure Hash Algorithm 2 521-bit as a secure host algorithm on the ICX device.
ssh-rsa
Enables Secure Shell Rivest Shamir Adleman as a secure host algorithm on the ICX device.
ssh-ed25519
Enables Secure Shell Ed25519 as a secure host algorithm on the ICX device.
Modes

Global configuration mode

Usage Guidelines

One or more host key algorithms can be specified per command line.

The no form of the command deactivates the specified host key method or methods.

Examples

The following example enables ecdsa-sha2-nistp256 and ecdsa-sha2-nistp384 as secure host key algorithms on the ICX device.

device# configure terminal
device(config)# ip ssh host-key-method ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 
History
Release version Command history
10.0.10c This command was introduced.