Skip to content

Configure the SSH Client

  1. Enable the SSH Client.

    Run the TCP/IP Services configuration utility:

    $ @SYS$STARTUP:TCPIP$CONFIG.COM
    

    From the available options, select Client components, then SSH Client, and then Enable & Start service on this node.

  2. Confirm that Public Key Authentication is allowed.

    Public key authentication is enabled by default. However, if the AllowedAuthentications setting has been modified, you may need to explicitly include publickey in the list of permitted authentication methods.

    For example:

    $ EDIT TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2]SSH2_CONFIG
    
    AllowedAuthentications publickey
    
  3. Generate a Key Pair.

    Create an SSH directory if needed:

    $ CREATE/DIRECTORY DKA0:[SMITH.SSH2]
    
    Generate the key:
    $ @SYS$MANAGER:TCPIP$DEFINE_COMMANDS.COM
    $ SET DEFAULT DKA0:[SMITH.SSH2]
    $ ssh_keygen key_filename
    The utility prompts for a passphrase twice. Enter a passphrase for additional security, or leave it blank for batch or automated use.

    A private key and public key (KEY_FILENAME.PUB) are created.

    Protect the files as follows:

    SET FILE/PROTECTION=(S,W,G,O:RWED) KEY_FILENAME.*
    
  4. Create the IDENTIFICATION file and add the private key name.

    $ CREATE DKA0:[SMITH.SSH2]IDENTIFICATION
    
    IdKey key_filename
    

    Note: Do not include a file version such as ;1.

  5. Transfer the Public Key to the server.

    Use SFTP:

    sftp user@server
    cd ssh2
    put KEY_FILENAME.PUB

    Note: If the SSH server has not yet been enabled, skip this step and return to it after the server configuration is complete.