User Manual
101Rack ATS AP44xx User Manual
Configure SSH host key
Path: Configuration > Network > Console >
SSH Host Key
Status indicates the status of the host key (private key):
• SSH Disabled: No host key in use: When disabled, SSH cannot use a host key.
• Generating: The Rack ATS is creating a host key because no valid host key was found.
• Loading: A host key is being activated on the Rack ATS.
• Valid: One of the following valid host keys is in the /ssh directory (the required location on the
Rack ATS):
– A 1024-bit or 2048-bit host key created by the Security Wizard
– A 2048-bit RSA host key generated by the Rack ATS
Certificate Action:
• Add or Replace: Browse to and upload a host key file created by the Security Wizard.
To use the Security Wizard, see the Security Handbook, available at www.apc.com.
NOTE: To reduce the time required to enable SSH, create and upload a host key in advance. If
you enable SSH with no host key loaded, the Rack ATS takes up to one minute to create a host
key, and the SSH server is not accessible during that time.
• Host Key Fingerprint: A fingerprint helps authenticate a server. If the Security Wizard is used to
generate the host key, it also generates the fingerprint, which is displayed here when SSH is
enabled and the host key is in use. When you first connect to the device using SSH, compare the
fingerprint presented by the SSH client to the fingerprint that the Security Wizard generated to
ensure that they match. (Almost all SSH clients display the fingerprint.)
• Remove: Remove the current host key.
NOTE: To use SSH, you must have an SSH client installed. Most Linux and other UNIX
platforms include
an SSH client, but Microsoft Windows operating systems do not. Clients are available from various
vendors.
SNMP options
All user names, passwords, and community names for SNMPv1 are transferred over the network as
plain text. If your network requires the high security of encryption, disable SNMPv1 access and use
SNMPv3 instead.
When using StruxureWare to manage a Rack ATS on the public network, you must have the same
version of SNMP (1 or 3) enabled on both the Rack ATS interface and the StruxureWare interface. Read
access will allow the StruxureWare to receive traps from the Rack ATS, but Write access is required
while you set the StruxureWare as a trap receiver.
For detailed information on enhancing and managing the security of your system, see the Security
Handbook, available at www.apc.com.