The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

SSH public key based authentication for Manager Appliance (Linux)

Prev Next

You can use SSH public key authentication or password based authentication to login to the Manager or the remote machine using SSH. Use of public key authentication allows administrators and users to access the Manager or the remote machine without the use of password based authentication.

Manager as the SSH client

When the Manager serves as the SSH client, you can SCP files to a remote machine serving as a SCP server from the Manager. This requires the SSH public key generated on the Manager to be configured on the remote SCP server. The Manager uploads the key to the remote SCP sever. Perform the following steps to access the SCP server on a remote machine from the Manager:

  1. Login to the Manager appliance with the username and password.
  2. Execute the publicKeyAuth command .
  3. Choose Upload Key To A Server and press Enter.
  4. Enter the SCP server IP address.
  5. Enter the SCP server username.
  6. Enter the SCP server password to transfer the public key to the remote machine.

    The public key is successfully uploaded to the remote machine.

  7. To check if the key is uploaded, try logging into the machine, with ssh <username>@<SCP server IP address>.

    The SSH public key based authentication is successful.

Sample output

MLOS-78> publicKeyAuth

Choose one of the below options

1: Upload Key To A Server

2: Download Key From Client

Input [1] or [2] : 1

[sudo] password for admin:

Please provide with the following inputs.

[Thu Feb 20 10:57:44 UTC 2020] : Enter The SCP Server IP : 10.1.1.1

[Thu Feb 20 10:57:44 UTC 2020] : Enter SCP Server UserName : admin

[Thu Feb 20 10:57:44 UTC 2020] : Checking if .ssh/ already exists.

[Thu Feb 20 10:57:44 UTC 2020] : The /home/admin/.ssh already exists!

[Thu Feb 20 10:57:44 UTC 2020] : Checking if public key already exists.

[Thu Feb 20 10:57:44 UTC 2020] : The /home/admin/.ssh/id_ecdsa.pub does not exists!

[Thu Feb 20 10:57:44 UTC 2020] : Creating a key pair.

Generating public/private ecdsa key pair.

Your identification has been saved in /home/admin/.ssh/id_ecdsa.

Your public key has been saved in /home/admin/.ssh/id_ecdsa.pub.

The key fingerprint is:

SHA256:7M1msETM8MRYZGqNnRDx+OV/anEOCQfxcbAUe2q+Dno admin@MLOS-78

The key's randomart image is:

+---[ECDSA 256]---+

| +B+ ..=o.|

| oXo..o = |

|=*= ..+ .|

|. .=+. .o |

|.o So...|

| .o. .+o. |

|..o. .=+ .|

|. o..+E+ |

| o..o. .|

+----[SHA256]-----+

[Thu Feb 20 10:57:44 UTC 2020] : Successfully created the key pair.

[Thu Feb 20 10:57:44 UTC 2020] : Changing permissions of local .ssh/ dir

[Thu Feb 20 10:57:44 UTC 2020] : Successfully changed the permissions of the dir/file to 700

[Thu Feb 20 10:57:44 UTC 2020] : Transfering public key to remote machine. The operation might ask for password.

/usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/home/admin/.ssh/id_ecdsa.pub"

/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed

/usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys

FIPS mode initialized

admin@10.1.1.1's password:

Number of key(s) added: 1

Now try logging into the machine, with: "ssh 'admin@10.1.1.1'"

and check to make sure that only the key(s) you wanted were added.

[Thu Feb 20 10:57:44 UTC 2020] : Successfully copied the key to 10.1.1.1

[Thu Feb 20 10:57:44 UTC 2020] : Modifying .ssh/ related dir/file permissions on the remote machine. The operation might ask for password.

FIPS mode initialized

[Thu Feb 20 10:57:44 UTC 2020] : Successfully modified the permissions of .ssh/authorized_keys on remote machine.

Manager as the SSH server

When the Manager serves as the SSH server, you can SCP files from a remote machine serving as a SCP client to the Manager. This requires the SSH public key generated on the remote SCP client to be configured on the Manager. The Manager downloads the key from the remote SCP client. Perform the following steps to access the Manager from the SCP client on a remote machine:

  1. Login to the Manager appliance with the username and password.
  2. Execute the publicKeyAuth command.
  3. Choose Download Key From Client and press Enter.
  4. Enter the SCP client IP address.
  5. Enter the SCP client username.
  6. Enter the public key file location given on the SCP client machine.
  7. Enter the SCP client password to transfer the public key to the remote machine.

    The public key is successfully downloaded from the remote machine. The SSH public key based authentication is successful.

Sample output

MLOS-78> publicKeyAuth

Choose one of the below options

1: Upload Key To A Server

2: Download Key From Client

Input [1] or [2] : 2

[sudo] password for admin:

Please provide with the following inputs.

[Thu Feb 20 10:51:14 UTC 2020] : Enter The SCP Client IP : 10.1.1.1

[Thu Feb 20 10:51:14 UTC 2020] : Enter SCP Client UserName : admin

[NOTE] : Please Make Sure The Public Key Is Generated Using ECDSA

[Thu Feb 20 10:51:14 UTC 2020] : Public Key File Location On Client : /home/admin/.ssh/id_ecdsa.pub

[Thu Feb 20 10:51:14 UTC 2020] : The /home/admin/.ssh already exists!

[Thu Feb 20 10:51:14 UTC 2020] : Changing permissions of local .ssh/ dir

[Thu Feb 20 10:51:14 UTC 2020] : Successfully changed the permissions of the dir/file to 700

[Thu Feb 20 10:51:14 UTC 2020] : Downloading Public Key from Client : 10.1.1.1 to Server

FIPS mode initialized

admin@10.1.1.1's password:

id_ecdsa.pub 100% 177 326.2KB/s 00:00

[Thu Feb 20 10:51:14 UTC 2020] : Validating Public Key Algorithm

Download Successful

[Thu Feb 20 10:51:14 UTC 2020] : Resetting the permissions of the file .ssh/authorized_keys on local machine

[Thu Feb 20 10:51:14 UTC 2020] : Successfully modified the permissions of .ssh/authorized_keys on remote machine.