Enabling RSA Challenge-Response and Password Authentication

After the SSH server on the device negotiates a session key and encryption method with the connecting client, user authentication takes place. On RUCKUS ICX devices, SSH supports the following authentication methods, used separately or together:

  • Public-key: Enables the RSA key pair method, in which the public and private key are checked for a match before the client is authenticated.
  • Password: Allows the user to log in with username and password. Users are prompted for a password when they attempt to log in. If there is no user account that matches the username and password supplied by the user, the user is not granted access.
  • Interactive: On the RUCKUS ICX device, a form of challenge-response in which the username and password serve as the challenge and response.

Note: To disable username and password authentication, you must disable both the password and interactive methods of authentication.
Note: If you disable all forms of authentication, the SSH server is disabled.

All three authentication methods are enabled by default. Perform the following steps if necessary to change challenge-response configuration.

  1. (Optional) To check the current challenge-response authentication settings, enter the show ip ssh config command.
    device# show ip ssh config
    SSH server                 : Disabled
    SSH port                   : tcp\22
    Host Key                   :
    Encryption                 : aes256-cbc, aes192-cbc, aes128-cbc, aes256-ctr, aes
    192-ctr, aes128-ctr, 3des-cbc
    Permit empty password      : No
    Authentication methods     : Password, Public-key, Interactive
    Authentication retries     : 3
    Login timeout (seconds)    : 120
    Idle timeout (minutes)     : 0
    Strict management VRF      : Disabled
    SCP                        : Enabled
    SSH IPv4 clients           : All
    SSH IPv6 clients           : All
    SSH Client Keys            : RSA(0)
    Client Rekey               : 200 Minute, 0 KB
    Server Rekey               : 250 Minute, 0 KB
    
    The example shows public-key, password, and interactive authentication are enabled.
  2. If necessary, enable public-key authentication.
    device# configure terminal
    device(config)# ip ssh key-authentication yes
  3. If desired, enable password authentication.
    device# configure terminal
    device(config)# ip ssh password-authentication yes
    When password authentication is enabled, a password is required unless the "allow empty password" option has been enabled.
  4. If desired, enable interactive keyboard authentication.
    device# configure terminal
    device(config)# ip ssh interactive-authentication yes

Note: The no form of any of the previous commands disables that form of authentication.

The following example re-enables public-key authentication.

device# configure terminal
device(config)# ip ssh key-authentication yes

The following example disables username and password authentication but enables public key authentication.

Note: One authentication method must be enabled. If you attempt to disable all three authentication methods, the action is prevented, and an error message is displayed.

device# configure terminal
device(config)# ip ssh key-authentication yes
device(config)# ip ssh interactive-authentication no
device(config)# ip ssh password-authentication no