CLI Reference Guide-R04

Table Of Contents
Chapter 8
| User Authentication Commands
Secure Shell
– 271 –
ip ssh crypto
host-key generate
This command generates the host key pair (i.e., public and private).
Syntax
ip ssh crypto host-key generate
Default Setting
Generates RSA key pairs.
Command Mode
Privileged Exec
Command Usage
The switch uses only RSA Version 1 for SSHv1.5 clients and SSHv2 clients.
This command stores the host key pair in memory (i.e., RAM). Use the ip ssh
save host-key command to save the host key pair to flash memory.
Some SSH client programs automatically add the public key to the known hosts
file as part of the configuration process. Otherwise, you must manually create a
known hosts file and place the host public key in it.
The SSH server uses this host key to negotiate a session key and encryption
method with the client trying to connect to it.
Example
Console#ip ssh crypto host-key generate dsa
Console#
Related Commands
ip ssh crypto zeroize (271)
ip ssh save host-key (272)
ip ssh crypto zeroize This command clears the host key from memory (i.e. RAM).
Syntax
ip ssh crypto zeroize
Default Setting
Clears the RSA key.
Command Mode
Privileged Exec
Command Usage
This command clears the host key from volatile memory (RAM). Use the no ip
ssh save host-key command to clear the host key from flash memory.