<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I'm going to guess a software in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912516#M912977</link>
    <description>&lt;P&gt;&lt;SPAN mce-data-marked="1"&gt;I'm going to guess a software bug. &amp;nbsp;I don't use that exact feature, but&amp;nbsp;9.6(1) has been working pretty good for us.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 05:51:36 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-05-13T05:51:36Z</dc:date>
    <item>
      <title>Cisco ASA ssh public key authentication</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912515#M912973</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;I have ASA 5515-X with "Cisco Adaptive Security Appliance Software Version 9.4(2)11".&lt;/P&gt;
&lt;P&gt;I configure ssh public key&amp;nbsp;authentication (RSA 2048).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;
&lt;P&gt;username asauser&amp;nbsp;password XXXXXXXXXXXXXXXX&amp;nbsp;encrypted privilege 15&lt;/P&gt;
&lt;P&gt;username &lt;SPAN&gt;asauser&amp;nbsp;&lt;/SPAN&gt;attributes&lt;BR /&gt;service-type admin&lt;BR /&gt; ssh authentication publickey YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY&amp;nbsp;hashed&lt;/P&gt;
&lt;P&gt;When i connect putty with instakk key, &amp;nbsp;i can see messages:&lt;/P&gt;
&lt;P&gt;"Authenticating with public key "rsa-key-2048" from agent&lt;BR /&gt;Server refused public-key signature despite accepting key!&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And password promt&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;============================================================&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In ASA debug ssh 10:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Device ssh opened successfully.&lt;BR /&gt;SSH1: SSH client: IP = '192.168.60.100' interface # = 3&lt;BR /&gt;SSH: host key initialised&lt;BR /&gt;SSH1: starting SSH control process&lt;BR /&gt;SSH1: Exchanging versions - SSH-2.0-Cisco-1.25&lt;/P&gt;
&lt;P&gt;SSH1: send SSH message: outdata is NULL&lt;/P&gt;
&lt;P&gt;server version string:SSH-2.0-Cisco-1.25&lt;BR /&gt;SSH1: receive SSH message: 83 (83)&lt;BR /&gt;SSH1: client version is - SSH-2.0-PuTTY_Snapshot_2016_04_08.f0f19b6&lt;/P&gt;
&lt;P&gt;client version string:SSH-2.0-PuTTY_Snapshot_2016_04_08.f0f19b6&lt;/P&gt;
&lt;P&gt;SSH2 1: SSH2_MSG_KEXINIT sent&lt;BR /&gt;SSH2 1: SSH2_MSG_KEXINIT received&lt;BR /&gt;SSH2: kex: client-&amp;gt;server aes256-ctr hmac-sha1 none&lt;BR /&gt;SSH2: kex: server-&amp;gt;client aes256-ctr hmac-sha1 none&lt;BR /&gt;SSH2 1: expecting SSH2_MSG_KEXDH_INIT&lt;BR /&gt;SSH2 1: SSH2_MSG_KEXDH_INIT received&lt;BR /&gt;SSH2 1: signature length 271&lt;BR /&gt;SSH2: kex_derive_keys complete&lt;BR /&gt;SSH2 1: newkeys: mode 1&lt;BR /&gt;SSH2 1: SSH2_MSG_NEWKEYS sent&lt;BR /&gt;SSH2 1: waiting for SSH2_MSG_NEWKEYS&lt;BR /&gt;SSH2 1: newkeys: mode 0&lt;BR /&gt;SSH2 1: SSH2_MSG_NEWKEYS receivedSSH(&lt;SPAN&gt;asauser&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; user authen method is 'use AAA', aaa server group ID = 1&lt;BR /&gt;SSH(&lt;SPAN&gt;asauser&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; user authen method is 'use AAA', aaa server group ID = 1&lt;/P&gt;
&lt;P&gt;SSH2 0: key lookup succeeded&lt;BR /&gt;SSH2 1: Sent SSH2_MSG_USERAUTH_PK_OK to client&lt;BR /&gt;SSH2 0: channel window adjust message received 8233SSH(&lt;SPAN&gt;asauser&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; user authen method is 'use AAA', aaa server group ID = 1&lt;/P&gt;
&lt;P&gt;public key pkt&lt;/P&gt;
&lt;P&gt;00000014d1f329cb b889102384e5df4f f80c3ed980b03efc 3200000008767361&lt;BR /&gt;7a616e6f76000000 0e7373682d636f6e 6e656374696f6e00 0000097075626c69&lt;BR /&gt;636b657901000000 077373682d727361 0000011500000007 7373682d72736100&lt;BR /&gt;0000012500000101 00b33b265333d53a 724f2ae9af23ac7a fe4b8b9e27197ea6&lt;BR /&gt;0fb72e5a3c478597 3ab07cdf2f8d3b1b ce332b5d1662b7b7 5a9f4098eac9f361&lt;BR /&gt;20bfc7ae3d897a58 21d87ddc7884e3e9 79f4dbf207fa0119 80cc054a6bc94c02&lt;BR /&gt;3dff6dea738668a3 ea7e1b16bf4e5c37 67cf0716bc81cf6c 129e9e4a5dc01875&lt;BR /&gt;ac668da532834c13 1ce857d33548c36b 722ad831f569a4c0 0f732a165e99c138&lt;BR /&gt;2afbed6e9a6c4433 48862fdd9b45883c ec0f4f5b1ada8ffd 9ba2c31b08800acc&lt;BR /&gt;d537bc9ed82a5a09 cb4bb50f8dd33483 184595c9bad651e9 017a573e094a15b8&lt;BR /&gt;cd2640a735042a6f 9fa688fd78d0aff0 570700de7686bf26 af7408d56fc68b35&lt;BR /&gt;8a4e1bcdda8bfd7e e1&lt;/P&gt;
&lt;P&gt;SSH2 0: key lookup succeeded&lt;BR /&gt;SSH2 0: Signature verification succeeded&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How i can fix it, and auth over rsa pub key?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best regurds,&lt;/P&gt;
&lt;P&gt;Slava&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912515#M912973</guid>
      <dc:creator>sun_sazanov</dc:creator>
      <dc:date>2020-02-21T13:49:07Z</dc:date>
    </item>
    <item>
      <title>I'm going to guess a software</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912516#M912977</link>
      <description>&lt;P&gt;&lt;SPAN mce-data-marked="1"&gt;I'm going to guess a software bug. &amp;nbsp;I don't use that exact feature, but&amp;nbsp;9.6(1) has been working pretty good for us.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 05:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912516#M912977</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-05-13T05:51:36Z</dc:date>
    </item>
    <item>
      <title>Tnahks,
Best regurds,
Slava</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912517#M912980</link>
      <description>&lt;P&gt;Tnahks,&lt;/P&gt;
&lt;P&gt;Best regurds,&lt;/P&gt;
&lt;P&gt;Slava&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 11:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ssh-public-key-authentication/m-p/2912517#M912980</guid>
      <dc:creator>sun_sazanov</dc:creator>
      <dc:date>2016-05-13T11:21:37Z</dc:date>
    </item>
  </channel>
</rss>

