SSH Host Keys Regeneration
Feature Overview
- What is the name of the
feature? (What do users call the feature? If the feature is referred to by
an acronym, what is the acronym expansion? What is the formal name to be
used in documentation?)
Note: Typically, the name is used as part of the section titles, such as the overview title and the configuration section titles.
- Where does the feature fit within our taxonomy? (What are the taxonomy group and sub-group? This information is important for categorizing the feature documentation and incorporating it into the existing document sets.)
- What standard or standards govern the feature? (Sometimes needed.)
- Is the feature a new feature or an enhancement to an existing feature?
- Does the feature replace another feature?
- What does the feature do? (General description)
- How does the feature benefit the user?
- What set of terms do the writer and reader need to know to understand the feature and its use?
- How does the feature work? (Detailed description, if needed.)
To enhance security, Cloudpath release 6.0 introduces the ability to update/regenerate the SSH host key for each virtual machine (VM). Periodically changing SSH host keys can reduce the likelihood of man-in-the-middle (MITM) attacks on SSH. These host keys can be regenerated as needed to maintain robust session secrecy and integrity. Administrators can manually regenerate host keys through the user interface or command-line interface to proactively safeguard against potential cryptographic attacks.
Requirements
This feature has no special hardware or software requirements for feature enablement or usage.
If there are no requirements, use the following default wording:
This feature has no special hardware or software requirements for feature enablement or usage.
If there are requirements, include the applicable below points (depending on product line):
- What releases support the
feature?
Note: Typically, this is not documented in the configuration guides; however, we need to know where to include the information.
- What hardware models support the feature?
- Does the feature require specific modules?
- Does the feature run only on certain ports?
- Does the feature have special memory requirements?
- In an integrated system, can the feature be managed or configured from another device? What are the related release and system requirements?
- Does the feature introduce new user requirements?
- Does the feature introduce physical or location-based requirements?
Considerations
This feature has no special considerations or limitations pertaining to feature enablement or usage.
If there are no considerations, use the following default wording:
This feature has no special considerations or limitations pertaining to feature enablement or usage.
If there are considerations, include the applicable below points (depending on product line).
- Does the feature replace an existing feature?
- Does the feature work only with a certain protocol or with a limited set of protocols?
- Is the feature meant to be used in combination with another feature or a set of features?
- Is the feature incompatible with any features?
- What happens when the feature is enabled?
- What happens when the feature is disabled?
- Does enabling/disabling the feature enable/disable another feature?
- What system behavior changes, if any, does the feature introduce?
- Are performance issues associated with the feature? How can these be mitigated?
Best Practices
This feature has no special recommendations for feature enablement or usage.
If there are no best practices (recommendations), use the following default wording:
This feature has no special recommendations for feature enablement or usage.
If there are considerations, include the applicable below points (depending on product line).
Prerequisites
This feature has no prerequisites to feature enablement or usage.
If there are no prerequisites, use the following default wording:
This feature has no prerequisites to feature enablement or usage.
If there are prerequisites, include the applicable below points (depending on product line).
Limitations
The host key regeneration feature is only available to on-premises virtual machine installations. This feature is not available to Cloud Hosted customers.
The intention of this new template is to outline the information that you will need to collect from SMEs and provide to readers.
NOTE: Feature Configuration / Troubleshooting are *not* part of the Feature Concept template. These templates are likely to be part of seperate task/reference templates (to be developed).