You can use SSH public key authentication or password based authentication to login to the Sensor/remote machine using SSH. Use of public key authentication allows administrators and users to access the Sensor or the remote machine without the use of password based authentication.
Sensor as the SSH server
You can access the Sensor remotely using SSH from a remote machine. The SSH public key from the remote machine has to be configured in the Sensor. Since the Sensor does not permit any key to be exported by the remote client, you must import the key explicitly for every user.
The steps to access Sensor through SSH from a remote machine is as follows:
Generate the key pair (SSH public and private keys) for a user accessing the Sensor through a remote machine.
Add the user to the Sensor using
adduserCLI command.Set SCP server IP address from where the SSH public key is to be imported to the Sensor to login.
Import your SSH public key to the Sensor using the
importsshpublickeyCLI command.Sensor updates the SSH local repository with the SSH public key.
When you login to the Sensor using the SSH key, the Sensor authenticates the user with the SSH public key stored in the local repository.
Note
The sensor accepts both RSA and ECDSA public keys for user authentication. DSA is not supported.
Sensor as the SSH client
You can SCP files to a remote machine serving as a SCP server from the Sensor. This requires the Sensor SSH public key to be configured on the remote SCP server for the user. The Sensor exports this key to the remote SCP server if permitted to do so.
The steps to configure Sensor's ssh public key on remote machine are as follows:
The Sensor generates a public-private key (ECDSA) pair using the SSH utility "ssh-keygen".
The Sensor retains the private-key and exports the SSH public key to the remote machine using
exportsshpublickeyCLI command.Note
The
exportsshpublickeyCLI command exports the Sensor's SSH public key to the configured SCP server.Note
The
exportsshpublickeyCLI command exports the Sensor's SSH public key to the remote machine only by password based authentication.There are two outcomes while executing
exportsshpublickeyCLI command:When the public key of the Sensor is directly configured on the remote machine:
intruShell@ips-ns9500#> exportsshpublickey <path>Please enter the SCP User Name : emb-demoPlease enter the SCP User Password :Public Key configured on the remote machineIn this scenario, the Sensor successfully configures the SSH public key on the remote machine.
When the public key is not configured but just copied on the remote machine:
intruShell@ips-ns9500#> exportsshpublickey <path>Please enter the SCP User Name : emb-demoPlease enter the SCP User Password :Transfer Successful through scp, User need to configure the public key manually on the remote machine.In this scenario, the Sensor fails to configure the SSH public key on the remote machine, but a copy of it is saved in the file path provided (
<path>) in the remote machine. You need to manually configure the SSH public key on the remote machine'sauthorized_keysfile.
Note
If the SSH public key authentication fails, the Sensor will use password based authentication method.
Warning
The SSH public key authentication could fail due to incorrect permission of authorized keys; change the mode of
authorized_keysfile to 600 and try again.