Configure the SSH Server¶
-
Enable the SSH Server.
Run the TCP/IP Services configuration utility:
From the available options, select Server components, then SSH, and then Enable & Start service on this node.$ @SYS$STARTUP:TCPIP$CONFIG.COMA server host key is created if one does not already exist.
-
Confirm Public Key Authentication is Allowed.
Public key authentication is enabled by default. However, if the AllowedAuthentications setting has been modified, you may need to explicitly include publickey in the list of permitted authentication methods.
For example:
$ TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2]SSHD2_CONFIG $ AllowedAuthentications publickey -
Verify the Public Key.
Ensure the user's SSH directory exists and the public key has been copied from the client.
Verify the key:
$ @SYS$MANAGER:TCPIP$DEFINE_COMMANDS.COM $ SET DEFAULT DKA0:[SMITH.SSH2] $ ssh_keygen -"F" key_filename.pubA fingerprint should be returned. If no fingerprint is displayed, the key is not usable.
If the key originated from OpenSSH, convert it to SSH.COM format before use.
$ ssh-keygen -e -f openssh_key.pub > key_filename.pub -
Set File Protection.
Protect the public key file:
$ SET FILE/PROTECTION=(S,W,G,O:RWED) key_filename.pub -
Create the AUTHORIZATION File.
$ CREATE DKB0:[SMITH.SSH2]AUTHORIZATION.Each entry consists of a single line containing the public key filename, for example:
KEY key_filename.pubNote: Do not include a file version such as
;1.