Implementation

The client public key file format allows for a username to be provided in the "Subject" field the SSH2 public key. Additional private headers can be used. There are three privilege levels: 0 READ-WRITE/ADMINISTRATOR, 4 PORT-CONFIG, and 5 READ-ONLY.

After decoding the base64 encoded public keys to binary format, a SHA256 hash of the binary format key is created. This hash is saved to memory. The hash is verified as unique compared to all the hashes of client public keys that have already been parsed. Non-empty usernames are also verified as unique compared to the usernames already parsed in the public key. Access is denied if the usernames are mismatched.

The username has the following restrictions:

  • The username cannot contain control characters, spaces, ", #, ?, |, or characters above ASCII code 0x7F.
  • The username must be less than or equal to 48 characters.
  • The username must be specified with the public key for that key to allow access. The user must specify a non-empty username in the login request.