The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

SSH public key based authentication for Sensor

Prev Next

You can use SSH public key authentication or password based authentication to login to the Sensor/remote machine using SSH. Use of public key authentication allows administrators and users to access the Sensor or the remote machine without the use of password based authentication.

Sensor as the SSH server

You can access the Sensor remotely using SSH from a remote machine. The SSH public key from the remote machine has to be configured in the Sensor. Since the Sensor does not permit any key to be exported by the remote client, you must import the key explicitly for every user.

The steps to access Sensor through SSH from a remote machine is as follows:

  1. Generate the key pair (SSH public and private keys) for a user accessing the Sensor through a remote machine.
  2. Add the user to the Sensor using adduser CLI command.
  3. Set SCP server IP address from where the SSH public key is to be imported to the Sensor to login.
  4. Import your SSH public key to the Sensor using the importsshpublickey CLI command.
  5. Sensor updates the SSH local repository with the SSH public key.
  6. When you login to the Sensor using the SSH key, the Sensor authenticates the user with the SSH public key stored in the local repository.

Sensor as the SSH client

You can SCP files to a remote machine serving as a SCP server from the Sensor. This requires the Sensor SSH public key to be configured on the remote SCP server for the user. The Sensor exports this key to the remote SCP server if permitted to do so.

The steps to configure Sensor's ssh public key on remote machine are as follows:

  1. The Sensor generates a public-private key (ECDSA) pair using the SSH utility "ssh-keygen".
  2. The Sensor retains the private-key and exports the SSH public key to the remote machine using exportsshpublickey CLI command.

    Note

    The exportsshpublickey CLI command exports the Sensor's SSH public key to the configured SCP server.

    Note

    The exportsshpublickey CLI command exports the Sensor's SSH public key to the remote machine only by password based authentication.

    There are two outcomes while executing exportsshpublickey CLI command:

    • When the public key of the Sensor is directly configured on the remote machine:

      IntruDbg#> exportsshpublickey <path>

      Please enter the SCP User Name : emb-demo

      Please enter the SCP User Password :

      Public Key configured on the remote machine

      In this scenario, the Sensor successfully configures the SSH public key on the remote machine.

    • When the public key is not configured but just copied on the remote machine:

      IntruDbg#> exportsshpublickey <path>

      Please enter the SCP User Name : emb-demo

      Please enter the SCP User Password :

      Transfer Successful through scp, User need to configure the public key manually on the remote machine.

      In this scenario, the Sensor fails to configure the SSH public key on the remote machine, but a copy of it is saved in the file path provided (<path>) in the remote machine. You need to manually configure the SSH public key on the remote machine's authorized_keys file.

Note

If the SSH public key authentication fails, the Sensor reverts to password based authentication method.

Warning

The SSH public key authentication could fail due to incorrect permission of authorized keys; change the mode of authorized_keys file to 600 and try again.