The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

SSH public key based authentication for Manager Appliance (Linux)

Prev Next

You can use SSH public key authentication or password-based authentication to login to the Manager or the remote machine using SSH. Use of public key authentication allows administrators and users to access the Manager or the remote machine without using password-based authentication.

Manager as the SSH client

When the Manager acts as the SSH client, you can use SCP to transfer files from the Manager to a remote machine that is acting as an SCP server. This transfer requires the SSH public key generated on the Manager to be configured on the remote SCP server. The Manager uploads the key to the remote SCP server.

Perform the following steps to access the SCP server on a remote machine from the Manager:

Note:

  • To remove SSH keys, execute no ssh client user admin1 authorized-key sshv2 1.

  • To view the SSH connection, execute show ssh client.

  1. Login to the Manager appliance with the username and password.

  2. Create a test user on the Manager for key authentication:

    username <username> password <password> 
  3. Disable password-based authentication for the test user admin1 on the Manager:

    username admin1 disable password
  4. Copy the remote machine's public key from the SCP client to the Manager's authorized keys for the test user:

    ssh client user admin1 <authorized-key sshv2 "<RSA Public Key>"
  5. Test the SSH connection from the Manager (acting as the SSH client) to the remote machine (acting as the SCP server):

    [root@server .ssh]# ssh -vvv admin1@10.1.1.1

    Note

    • The verbose output following the test command is a standard security banner displayed by the remote machine upon connection and is not part of the configuration steps.

    • ECDSA based publick key authentication is not supported.