Configuring RSA Challenge-Response Authentication

With RSA challenge-response authentication, a collection of client public keys are stored on the RUCKUS ICX device. Only clients that have a private key that corresponds to one of the stored public keys can gain access to the RUCKUS ICX device using SSH.

With RSA challenge-response authentication enabled, the following events occur when a client tries to access the RUCKUS ICX device using SSH:

  1. The client sends its public key to the RUCKUS ICX device.
  2. The RUCKUS ICX device compares the client public key to those stored in memory.
  3. If there is a match, the RUCKUS ICX device uses the public key to encrypt a random sequence of bytes.
  4. The RUCKUS ICX device sends these encrypted bytes to the client.
  5. The client uses its private key to decrypt the bytes.
  6. The client sends the decrypted bytes back to the RUCKUS ICX device.
  7. The RUCKUS ICX device compares the decrypted bytes to the original bytes it sent to the client. If the two sets of bytes match, it means that the client private key corresponds to an authorized public key, and the client is authenticated.

    Setting up RSA challenge-response authentication consists of the following steps: