Juniper SSH Public Key Access
标签:
junipernetworksshpublic公钥 |
分类: Juniper技术学习 |
通过在VMX上模拟SSH 公共密钥登录。
参考链接: https://kb.juniper.net/InfoCenter/index?page=content&id=KB21577
1. 通过在%上生成公共和私有的密钥对
[edit]
root@JNCIE-R1# run start shell
root@JNCIE-R1% ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa):
/root/.ssh/id_rsa already exists.
Overwrite (y/n)? y
Enter
passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
e4:f4:35:80:b0:83:27:3a:e2:b7:1d:a9:bf:ad:f3:80 root@JNCIE-R1
The key's randomart image is:
+--[ RSA 2048]----+
|
|
|
|
|.
o
|.. ..
.
| . E
+
|
|
+-----------------+
2. 显示当有的公共和私有的密钥对
root@JNCIE-R1% cat id_rsa
-----BEGIN RSA PRIVATE KEY-----
MIIEogIBAAKCAQEAscpifmku
R2+nu0hpMDt0atz12i1nR1XQiMM
1AuLMHuVq3ZeCU7cIU+/aC5rwQkRJEnVJVcgY221uCvS
9/60rFtiIL35I1Q1P8RtPlIEKg
cseCsYnOUM6VFhYKEj2ZVl5h
xEe39qSM7xz8cW53VGrXb+z8+K88oy3TdPm8uwIDAQABAoIBA
LWPBDJ2uIXNQt4btUFuGvWPv
pyIaUw09rK9Qqq5AtRqQVPwA
LwYljG3hQa1xLnP6bl2F5u5m
VrE5ALgjD3AiO2XfvcuOC3N/2fbxFLsLNrFgUg/BU1l6U1+LkEc6KFDXcxqjdE/s
tuSbcpd1NjTeksuth7NR1GJz
iL2pnqECgYEA63P0Cv4ZVq34
vIVf5tf+iVX5ZEY1IUFOae8Jbg4hmVeZ
CNeqRHFoY9FwRkzrvJ5OOHKA
QXzHteNea4tZumI35awQZ3F+v9klQEUfrDoy7vfejEULyJBL
THSuYgreAz9OFPhG5bdLYqN1
FDEZvClNpuZZQXwuVD1ceivl
hZxSM99Xr7QrRWaZOBPwq3XU
uh8FQ/+ztEtRzqKgjxFPCAJoiv5qTAs
4OMyuHgd4c2rrWI0+sIqKQKBgBGjbiovlJmIMalmg
SqB7hZcPBdA7OnC3H8rNkpQ8
W9U370hEL91IBR7lRvoie1BB
aJp5AoGAd6TkoP88xYZsqgmf
Rb/mooM/Q4ZjI+5BqhhqrcUUg053LhQj5iYiMn
Q/02pnA1BI0gty11dkMkog741d
-----END RSA PRIVATE KEY-----
root@JNCIE-R1% cat id_rsa.pub
ssh-rsa
AAAAB3NzaC1yc2EAAAADAQAB
3. 创建用户Public关联公共密钥对
[edit]
root@JNCIE-R1# set system login user public
class super-user authentication load-key-file
/root/.ssh/id_rsa.pub
[edit]
root@JNCIE-R1# show system login user public | display set
set system login user public uid 2004
set system login user public class super-user
set system login user public authentication
ssh-rsa "ssh-rsa
AAAAB3NzaC1yc2EAAAADAQAB
4. 将步骤2中显示的公共和私有的密钥对,复制出来,放在PC客户端的同一个文件夹下
http://s11/mw690/002k0DaPzy7guuxLNweea&690SSH
5. 设备CRT,关联公钥对
http://s13/mw690/002k0DaPzy7guuAShSQdc&690SSH
6. 使用用户10.0.29.4登录连接时,无密码直接进入设备
http://s16/mw690/002k0DaPzy7guuBXFuf2f&690SSH
[edit]
root@JNCIE-R1# run show log messages| last
1
Nov 29 17:32:01

加载中…