Enable DSA or RSA Challenge-Response and Password Authentication
After the SSH server on the device negotiates a session key and encryption method with the connecting client, user authentication takes place. On RUCKUS ICX devices, SSH supports the following authentication methods, used separately or together:
- Public-key: Enables the RSA and DSA key pair methods, in which the public and private key are checked for a match before the client is authenticated.
- Password: Allows the user to log in with username and password. Provided empty password logins are not allowed, users are prompted for a password when they attempt to log in. If there is no user account that matches the username and password supplied by the user, the user is not granted access.
- Interactive: On the RUCKUS ICX device, a form of challenge-response in which the username and password serve as the challenge and response.
All three authentication methods are enabled by default. Perform the following steps if necessary to change challenge-response configuration.
- (Optional) To check the current challenge-response authentication settings, enter
the
show ip ssh configcommand.device# show ip ssh config SSH server : Disabled SSH port : tcp\22 Host Key : DSA 1024 Encryption : aes256-cbc, aes192-cbc, aes128-cbc, aes256-ctr, aes 192-ctr, aes128-ctr, 3des-cbc Permit empty password : No Authentication methods : Password, Public-key, Interactive <--- all types enabled by default Authentication retries : 3 Login timeout (seconds) : 120 Idle timeout (minutes) : 0 Strict management VRF : Disabled SCP : Enabled SSH IPv4 clients : All SSH IPv6 clients : All SSH IPv4 access-group : SSH IPv6 access-group : SSH Client Keys : RSA(0) Client Rekey : 0 Minute, 0 KB Server Rekey : 0 Minute, 0 KBThe example shows public-key, password, and interactive authentication are enabled. - If necessary, enable public-key authentication.
- If desired, enable password authentication.
When password authentication is enabled, a password is required unless the "allow empty password" option has been enabled.
- If desired, enable interactive keyboard authentication.
The following example re-enables public-key authentication.
device# configure terminal
device(config)# ip ssh key-authentication yes
The following example disables username and password authentication but enables public key-authentication.
device# configure terminal device(config)#ip ssh key-authentication yesdevice(config)#ip ssh interactive-authentication nodevice(config)#ip ssh password-authentication no