<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is ssh with pki possible? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026064#M921111</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found documentation that ssh login should be able using x509 certificates. At least in NX-OS. But I did not find any documentation HOW this can be configured. Does anybody has a hint for me, where I can find more documentation about this? Is it possible in IOS 15?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any hint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael Schwartzkopff&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:46:02 GMT</pubDate>
    <dc:creator>misch1942</dc:creator>
    <dc:date>2020-02-21T12:46:02Z</dc:date>
    <item>
      <title>Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026064#M921111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found documentation that ssh login should be able using x509 certificates. At least in NX-OS. But I did not find any documentation HOW this can be configured. Does anybody has a hint for me, where I can find more documentation about this? Is it possible in IOS 15?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any hint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael Schwartzkopff&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026064#M921111</guid>
      <dc:creator>misch1942</dc:creator>
      <dc:date>2020-02-21T12:46:02Z</dc:date>
    </item>
    <item>
      <title>Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026065#M921112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible, please refer to following document by Ivan Pepelnjak on his blog regarding SSH with PKI on IOS v15.0.&lt;/P&gt;&lt;P&gt;&lt;A href="http://blog.ioshints.info/2009/10/ssh-rsa-authentication-works-in-ios.html" rel="nofollow"&gt;ssh-rsa-authentication-works-in-ios&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 13:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026065#M921112</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2012-10-22T13:10:20Z</dc:date>
    </item>
    <item>
      <title>Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026066#M921113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought my qustion was clear enough. I asked about x509 certificates, not about RSA key pairs. For RSA keys I would have to extract the keys from the certificate and configure it on all 1000+ switches.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 13:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026066#M921113</guid>
      <dc:creator>misch1942</dc:creator>
      <dc:date>2012-10-22T13:20:20Z</dc:date>
    </item>
    <item>
      <title>Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026067#M921114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my mistake, kinda missed that part.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2012 15:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026067#M921114</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2012-10-22T15:28:27Z</dc:date>
    </item>
    <item>
      <title>Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026068#M921115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I finally found the answer. The ssh service on a cisco device can extract the keypair from the certificate on the PKI. But it cannot authenticate the user certificate against the CA on the PKI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least that is what I found after long experiments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael Schwartzkopff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 07:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/2026068#M921115</guid>
      <dc:creator>misch1942</dc:creator>
      <dc:date>2012-10-23T07:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/3819141#M921116</link>
      <description>&lt;P&gt;Ths document says that you can:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/secure-shell-ssh/212178-Configuring-SSH-with-x509-authentication.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/secure-shell-ssh/212178-Configuring-SSH-with-x509-authentication.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 id="fw-pagetitle" class="" data-owner="ID"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuration/15-mt/sec-pki-15-mt-book/sec-deploy-rsa-pki.html#GUID-44796FDC-72A0-4240-895A-CCA9DB62CAE6" target="_blank"&gt;Public Key Infrastructure Configuration Guide, Cisco IOS Release 15MT&lt;/A&gt;&lt;/H1&gt;</description>
      <pubDate>Wed, 13 Mar 2019 23:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/3819141#M921116</guid>
      <dc:creator>chad patterson</dc:creator>
      <dc:date>2019-03-13T23:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is ssh with pki possible?</title>
      <link>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/3819514#M921117</link>
      <description>I strongly suggest checking this out:&lt;BR /&gt;&lt;A href="https://www.pragmasys.com/products/support/cisco-2-factor" target="_blank"&gt;https://www.pragmasys.com/products/support/cisco-2-factor&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is how I have seen 2FA implemented with Cisco devices for pki ssh login.&lt;BR /&gt;&lt;BR /&gt;Is it possible in IOS 15?&lt;BR /&gt;Yes. As long as you are running 15.2.4 or higher you can utilize the solution provided above. If you have IOS devices running something lower than 15.2.4 you can still do pki ssh login. The process is a bit different. You have to create local user profiles and store their public key on your device. Regardless you can definitely accomplish this.&lt;BR /&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Thu, 14 Mar 2019 12:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-ssh-with-pki-possible/m-p/3819514#M921117</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-14T12:47:07Z</dc:date>
    </item>
  </channel>
</rss>

