R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
172
filename: Specifies the name of the file for saving the local host public key. The file name is a string of
case-insensitive characters excluding ./ and ../. The name cannot be dots (.), hostkey, serverkey, dsakey,
or ecdsakey, and cannot start with a slash (/).For more information about file name, see Fundamentals
Configuration Guide.
Usage guidelines
Whether the command exports or displays the host public key depends on the presence of the filename
argument.
You can use the command to display or export the local RSA host public keys before distributing it to a
peer device.
1. Save the local host public key to a file with one of the following methods:
{ Use the public-key local export rsa [ name key-name ] { openssh | ssh2 } command to display
the host public key in the specified format, copy and paste it to a file.
{ Use the public-key local export rsa [ name key-name ] { openssh | ssh2 } filename command to
export the host public key to the file. You cannot export the host public key to the folder pkey
and its subfolders.
2. Transfer a copy of the file to the peer device, for example, by using FTP or TFTP in binary mode.
3. On the peer device, use the public-key peer import sshkey command to import the host public key
from the file.
SSH1.5, SSH2.0 and OpenSSH are different public key formats. Choose the proper format that is
supported on the device where you import the host public key. In FIPS mode, the device only supports
SSH2.0 and OpenSSH.
Examples
# Export the host public key of the local RSA key pair with the default name in OpenSSH format to the
file key.pub.
<Sysname> system-view
[Sysname] public-key local export rsa openssh key.pub
# Display the host public key of the local RSA key pair with the default name in SSH2.0 format.
<Sysname> system-view
[Sysname] public-key local export rsa ssh2
---- BEGIN SSH2 PUBLIC KEY ----
Comment: "rsa-key-2013/05/12"
AAAAB3NzaC1yc2EAAAADAQABAAAAgQDapKr+/gTCyWZyabuCJuJjMeMPQaj/kixzOCCAl+hDMmEGMrSfddq/b
YcbgM7Buit1AgB3x0dFyTPi85DcCznTW4goPXAKFjuzCbGfj4chakSr+/aj1k3rM+XOvyvPJilneKJqhPT0xd
v4tlas+mLNloY0dImbwS2kwE71rgg1CQ==
---- END SSH2 PUBLIC KEY ----
# Display the host public key of the local RSA key pair with the default name in OpenSSH format.
<Sysname> system-view
[Sysname] public-key local export rsa openssh
ssh-rsa
AAAAB3NzaC1yc2EAAAADAQABAAAAgQDapKr+/gTCyWZyabuCJuJjMeMPQaj/kixzOCCAl+hDMmEGMrSfddq/b
YcbgM7Buit1AgB3x0dFyTPi85DcCznTW4goPXAKFjuzCbGfj4chakSr+/aj1k3rM+XOvyvPJilneKJqhPT0xd
v4tlas+mLNloY0dImbwS2kwE71rgg1CQ== rsa-key
# Export the host public key of the local RSA key pair rsa1 in OpenSSH format to the file rsa1.pub.
<Sysname> system-view
[Sysname] public-key local export rsa name rsa1 openssh rsa1.pub