Destroying A Local Asymmetric Key Pair; Specifying The Peer Public Key On The Local Device - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Step
2.
Display the local RSA or DSA
host public key in a specific
format.
Exporting the host public key in a specific format to a file
After you export and save the host public key in a specify format to a file, transfer the file to the peer
device.
To export and save the local host public key to a file:
Step
Enter system view.
1.
2.
Export and save the local
RSA/DSA host public key in a
specific format to a file.

Destroying a local asymmetric key pair

You may need to destroy a local asymmetric key pair and generate a new pair when an intrusion event
has occurred, the storage media of the device is replaced, the asymmetric key has been used for a long
time, the local certificate expires, or mode changes between FIPS and non-FIPS. The key pairs generated
in FIPS mode cannot be used in non-FIPS mode, and vice versa. For more information about the local
certificate, see
To destroy a local asymmetric key pair:
Step
1.
Enter system view.
2.
Destroy a local asymmetric key pair.

Specifying the peer public key on the local device

In some applications, such as SSH, to enable the local device to authenticate a peer device, specify the
peer public key on the local device. Take one of the following methods:
Method
Command
"Configuring
PKI."
Prerequisites
To display the local RSA host
public key in a specific format:
public-key local export rsa
{ openssh | ssh1 | ssh2 }
To display the local DSA host
public key in a specific format:
public-key local export dsa
{ openssh | ssh2 }
Command
system-view
To export and save the local RSA host
public key to a file:
public-key local export rsa { openssh |
ssh1 | ssh2 } filename
To export and save the local DSA host
public key to a file:
public-key local export dsa { openssh |
ssh2 } filename
Command
system-view
public-key local destroy { dsa | rsa }
158
Remarks
Use at least one command.
The ssh1 keyword is not available
for FIPS mode.
Remarks
N/A
Use at least one
command.
The ssh1 keyword is not
available for FIPS mode.
Remarks

Advertisement

Table of Contents
loading

Table of Contents