ip ssh key-authentication

Configures DSA or RSA challenge-response authentication.
Syntax
ip ssh key-authentication { yes | no }
no ip ssh key-authentication { yes | no }
Command Default

DSA or RSA challenge-response authentication is enabled by default.

Parameters
yes
Enables DSA or RSA challenge-response authentication. The default is yes.
no
Disables DSA or RSA challenge-response authentication.
Modes

Global configuration mode

Usage Guidelines

After the SSH server on the device negotiates a session key and encryption method with the connecting client, user authentication takes place. The implementation of SSH supports DSA or RSA challenge-response authentication and password authentication. You can deactivate one or both user authentication methods for SSH. Note that deactivating both authentication methods disables the SSH server entirely.

With DSA or RSA challenge-response authentication, a collection of clients’ public keys are stored on the device. Clients are authenticated using these stored public keys. Only clients that have a private key that corresponds to one of the stored public keys can gain access to the device using SSH.

The no form of the command disables DSA or RSA challenge-response authentication.

Examples

The following example enables DSA or RSA challenge-response authentication.

device(config)# ip ssh key-authentication