<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Login to FTD via SSH with Public/Private Key in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026785#M22721</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two FTD 2110 in high availability.&lt;/P&gt;&lt;P&gt;I have a script that needs to log in to the ssh of the FTD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask if there is a way the login process to use a pair of public/private key instead of username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2020 12:47:45 GMT</pubDate>
    <dc:creator>kostasthedelegate</dc:creator>
    <dc:date>2020-02-10T12:47:45Z</dc:date>
    <item>
      <title>Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026785#M22721</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two FTD 2110 in high availability.&lt;/P&gt;&lt;P&gt;I have a script that needs to log in to the ssh of the FTD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask if there is a way the login process to use a pair of public/private key instead of username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 12:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026785#M22721</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-10T12:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026806#M22722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no way login using private/public certificates instead of username/password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But what is the issue using username/password in the script you are using ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 13:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026806#M22722</guid>
      <dc:creator>Muhammad Awais Khan</dc:creator>
      <dc:date>2020-02-10T13:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026809#M22723</link>
      <description>They are plain text&lt;BR /&gt;I would like to hide them somehow</description>
      <pubDate>Mon, 10 Feb 2020 13:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4026809#M22723</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-10T13:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4027180#M22724</link>
      <description>&lt;P&gt;I don't think it can be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or make a script in a way that you will be entering password manually once.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 01:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4027180#M22724</guid>
      <dc:creator>Muhammad Awais Khan</dc:creator>
      <dc:date>2020-02-11T01:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4027298#M22725</link>
      <description>ok!&lt;BR /&gt;Thanks!!</description>
      <pubDate>Tue, 11 Feb 2020 06:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4027298#M22725</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-11T06:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4495064#M1084713</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sure, it can be done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on your FTD:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. make a local user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure user add user1 basic&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;configure user add user1 config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. go into "expert" mode and issue "sudo su"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;expert&lt;/P&gt;&lt;P&gt;sudo su&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. generate public and private key:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssh-keygen -t rsa -b 2048&lt;/P&gt;&lt;P&gt;/root/.ssh/id_rsa already exists.&lt;BR /&gt;Overwrite (y/n)? y&lt;BR /&gt;Enter passphrase (empty for no passphrase): [zostawić puste]&lt;BR /&gt;Enter same passphrase again: [zostawić puste]&lt;BR /&gt;Your identification has been saved in /root/.ssh/id_rsa.&lt;BR /&gt;Your public key has been saved in /root/.ssh/id_rsa.pub.&lt;BR /&gt;The key fingerprint is:&lt;BR /&gt;SHA256:v++aukga9RZhTONHweTN6oybKjeP876IOBZ59xNy5mM root@firepower&lt;BR /&gt;The key's randomart image is:&lt;BR /&gt;+---[RSA 2048]----+&lt;BR /&gt;| oo+. |&lt;BR /&gt;| + +.o |&lt;BR /&gt;| = o o |&lt;BR /&gt;| . o . |&lt;BR /&gt;| . . S . |&lt;BR /&gt;| o ..o.+* |&lt;BR /&gt;| o...*+.+ |&lt;BR /&gt;| o..=+=Eo o |&lt;BR /&gt;| ...oo=OX*++o |&lt;BR /&gt;+----[SHA256]-----+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. make catalog .ssh in the user1's home catalog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mkdir -p /home/user1/.ssh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. copy the generated public key to&amp;nbsp;file authorized_keys in the&amp;nbsp;/home/user1/.ssh directory:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cp /root/.ssh/id_rsa.pub /home/user1/.ssh/authorized_keys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now you can use the id_rsa file (which contains private key) in your script for user "user1" - below an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssh user1@192.168.0.1 -i /id_rsa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: change permission level for the file id_rsa using "chmod 400 id_rsa" command in case you get an error regarding the permission to id_rsa file like below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;BR /&gt;@ WARNING: UNPROTECTED PRIVATE KEY FILE! @&lt;BR /&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;BR /&gt;Permissions 0666 for '/bootflash/id_rsa' are too open.&lt;BR /&gt;It is required that your private key files are NOT accessible by others.&lt;BR /&gt;This private key will be ignored.&lt;BR /&gt;Load key "/bootflash/id_rsa": bad permissions&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 15:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4495064#M1084713</guid>
      <dc:creator>leszek.sroka</dc:creator>
      <dc:date>2021-10-29T15:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Login to FTD via SSH with Public/Private Key</title>
      <link>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4634795#M1091070</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried this, but even though Ieft the password blank I'm prompted with enter password and can't proceed.&lt;/P&gt;&lt;P&gt;Anny ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 10:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/login-to-ftd-via-ssh-with-public-private-key/m-p/4634795#M1091070</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2022-06-20T10:11:49Z</dc:date>
    </item>
  </channel>
</rss>

