10-21-2012 12:54 PM - edited 02-21-2020 04:46 AM
Hi,
I found documentation that ssh login should be able using x509 certificates. At least in NX-OS. But I did not find any documentation HOW this can be configured. Does anybody has a hint for me, where I can find more documentation about this? Is it possible in IOS 15?
Thanks for any hint.
Greetings,
Michael Schwartzkopff
10-22-2012 06:10 AM
It is possible, please refer to following document by Ivan Pepelnjak on his blog regarding SSH with PKI on IOS v15.0.
10-22-2012 06:20 AM
Hi,
I thought my qustion was clear enough. I asked about x509 certificates, not about RSA key pairs. For RSA keys I would have to extract the keys from the certificate and configure it on all 1000+ switches.
10-22-2012 08:28 AM
my mistake, kinda missed that part.
10-23-2012 12:56 AM
Hi,
I think I finally found the answer. The ssh service on a cisco device can extract the keypair from the certificate on the PKI. But it cannot authenticate the user certificate against the CA on the PKI.
At least that is what I found after long experiments.
Greetings,
Michael Schwartzkopff
03-13-2019 04:05 PM
03-14-2019 05:47 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide