Configure the SSH Client¶
-
Enable the SSH Client.
Run the TCP/IP Services configuration utility:
$ @SYS$STARTUP:TCPIP$CONFIG.COMFrom the available options, select Client components, then SSH Client, and then Enable & Start service on this node.
-
Confirm that Public Key Authentication is allowed.
Public key authentication is enabled by default. However, if the AllowedAuthentications setting has been modified, you may need to explicitly include publickey in the list of permitted authentication methods.
For example:
$ EDIT TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2]SSH2_CONFIG AllowedAuthentications publickey -
Generate a Key Pair.
Create an SSH directory if needed:
Generate the key:$ CREATE/DIRECTORY DKA0:[SMITH.SSH2]
The utility prompts for a passphrase twice. Enter a passphrase for additional security, or leave it blank for batch or automated use.$ @SYS$MANAGER:TCPIP$DEFINE_COMMANDS.COM $ SET DEFAULT DKA0:[SMITH.SSH2] $ ssh_keygen key_filenameA private key and public key (KEY_FILENAME.PUB) are created.
Protect the files as follows:
SET FILE/PROTECTION=(S,W,G,O:RWED) KEY_FILENAME.* -
Create the IDENTIFICATION file and add the private key name.
$ CREATE DKA0:[SMITH.SSH2]IDENTIFICATION IdKey key_filenameNote: Do not include a file version such as ;1.
-
Transfer the Public Key to the server.
Use SFTP:
sftp user@server cd ssh2 put KEY_FILENAME.PUBNote: If the SSH server has not yet been enabled, skip this step and return to it after the server configuration is complete.