Explains how a Cisco IOS XR SSH server permits selected password, keyboard-interactive, and public-key authentication methods and rejects attempts that use disabled methods.
Selective SSH server authentication is a control that
-
allows password, keyboard-interactive, and public-key methods to be disabled individually
-
limits clients to the remaining permitted methods, and
-
rejects login attempts that use a disabled method.
Public-key authentication includes certificate-based authentication. Disabling public-key authentication therefore disables certificate-based authentication.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Selective Authentication Methods for SSH Server |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
|
Selective Authentication Methods for SSH Server |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
|
Selective Authentication Methods for SSH Server |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100]) (select variants only*) *This feature is supported on:
|
|
Selective Authentication Methods for SSH Server |
Release 7.8.1 |
You now have the flexibility to choose the preferred SSH server authentication methods on the router. These methods include password authentication, keyboard-interactive authentication, and public-key authentication. This feature allows you to selectively disable these authentication methods. By allowing the SSH clients to connect to the server only through these permitted authentication methods, this functionality brings in additional security for router access through SSH. Before this release, by default, the SSH server allowed all these authentication methods for establishing SSH connections. The feature introduces these changes:
|