<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Login using only Public-Private Key and Priv Levels in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183660#M123603</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, that's not how its supposed to be ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you accidently use the "nopassword" keyword instead of removing the secret/password?&lt;/P&gt;&lt;P&gt;Wenn you do a "show run | i username" it should be in the form above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Mar 2013 10:39:51 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2013-03-20T10:39:51Z</dc:date>
    <item>
      <title>SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183655#M123598</link>
      <description>&lt;P&gt;Hey, I'm trying to make a setup on my Cisco 881 router, but I'm having some trouble.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've managed to configure logging in with a Public-Private key pair over SSH, but it's also still possible to log in over SSH with just a username and password. I'd like to prevent this, if possible. I imagine I might have manually configured this to be allowed at some point, but I can't quite figure out how I did this, as no matter what I've tried to remove, it keeps allowing this option. I still need to be able to log in with a username, because I want users to have different privileges. Which brings me to my second problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I've logged in using the Public-Private key, I don't automatically go into privilege mode, even though the user is configured with a privilege level. I'd like to configure that users that I've configured to use a certain privilege mode, automatically go into privilege mode without a password prompt. I know it did this before I started using the Public-Private key (or before I used AAA, which was configured around the same time), so I wondered if it's possible to do this still.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone needs a part of my configuration in order to help, just ask for the part that you need and I'll post it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for anyone trying to help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183655#M123598</guid>
      <dc:creator>NielsvdBerghe</dc:creator>
      <dc:date>2019-03-11T03:10:56Z</dc:date>
    </item>
    <item>
      <title>SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183656#M123599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Niels,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wrong section, try putting it in AAA, Identity and NAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 14:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183656#M123599</guid>
      <dc:creator>Chris Illsley</dc:creator>
      <dc:date>2013-03-11T14:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183657#M123600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've figured out how to make a user go straight into privilege mode and have lower ranking users not go into a higher privilege level. After configuring AAA, I used these commands:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;(config)#aaa authorization exec default local&lt;/P&gt;&lt;P&gt;(config)#aaa authorization console&lt;/P&gt;&lt;P&gt;(config)#enable secret password&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Now my last problem is with the SSH password login. I've configured to use a Public-Private keypair to login and this works just fine. The problem is that the router still allows people to log in using a regular password when they don't have a key. Anyone know how to fix this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 11:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183657#M123600</guid>
      <dc:creator>NielsvdBerghe</dc:creator>
      <dc:date>2013-03-19T11:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183658#M123601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To restrict users to only do pubkey-authentication you need to remove the secret/password from the regular user-account:&lt;BR /&gt;&lt;BR /&gt;username test privilege 15&lt;BR /&gt;&lt;BR /&gt;That way the user can only log in with the stored public key information and still gets directly to privilege 15.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 07:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183658#M123601</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-03-20T07:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183659#M123602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tried removing the password from the user, but it didn't quite work out. It still allows you to login without a key, only now you don't input anything when it asks for a password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 10:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183659#M123602</guid>
      <dc:creator>NielsvdBerghe</dc:creator>
      <dc:date>2013-03-20T10:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183660#M123603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, that's not how its supposed to be ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you accidently use the "nopassword" keyword instead of removing the secret/password?&lt;/P&gt;&lt;P&gt;Wenn you do a "show run | i username" it should be in the form above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 10:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183660#M123603</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-03-20T10:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183661#M123604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I do a "show run | i username", this is what I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin privilege 15&lt;/P&gt;&lt;P&gt;&amp;nbsp; username admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that I'm allowing the password prompt through a command I've used somewhere?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 10:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183661#M123604</guid>
      <dc:creator>NielsvdBerghe</dc:creator>
      <dc:date>2013-03-20T10:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Login using only Public-Private Key and Priv Levels</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183662#M123605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just tested it again and you are right. I completely remembered wrong about how that worked. You could specify a long and random password that the user doesn't know. That would restrict it to pubkey-logins. Not very elegant but should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 11:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-login-using-only-public-private-key-and-priv-levels/m-p/2183662#M123605</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-03-20T11:36:32Z</dc:date>
    </item>
  </channel>
</rss>

