Explains certificate and public-key trust models and provides requirements, configuration, verification, and key-management guidance for SSH clients and servers on Cisco IOS XR routers.
Use this chapter to select and configure X.509v3, OpenSSH certificate, or public-key authentication for SSH connections.
The chapter provides information in these functional areas:
-
X.509v3 server and user certificate authentication
-
OpenSSH CA, host-certificate, user-certificate, and TACACS+ integration
-
Public-key authentication from a router acting as an SSH client
-
Public-key authentication to a router acting as an SSH server
SSH certificate and public-key authentication
Explains how certificates, certificate authorities, and public-private key pairs authenticate SSH servers and users while avoiding the transmission of reusable passwords over the network.
X.509v3 certificate authentication
Explains how X.509v3 identity certificates and trusted CA signatures support SSH server and user authentication on Cisco IOS XR routers.
OpenSSH certificate authentication
Explains how an OpenSSH CA signs host and user certificates to establish mutual trust between a client and a Cisco IOS XR router.
TACACS+ authorization for OpenSSH certificate users
Explains how a router validates an OpenSSH user certificate and uses centralized TACACS+ profiles to authorize router access.
Public-key authentication for SSH clients
Explains how passwordless public-key authentication works when a Cisco IOS XR router acts as an SSH, SFTP, or SCP client for a locally configured user.
Public-key authentication to SSH servers
Explains how a Cisco IOS XR router stores public keys and authenticates SSH clients that prove possession of the corresponding private keys.