Host-key authentication can be used to prevent man-in-the-middle attacks, in which another server poses as the appliance or the Central Management System platform and intercepts the traffic between them. When the appliance and the Central Management System appliance connect the first time using a client-initiated connection, a key exchange takes place. The Central Management System appliance sends a copy of its host key to the appliance, where it is compared to the keys in the appliance's host-keys database.
If strict host-key checking is enabled, the connection can be established only if the key that is sent matches an entry in the local host-keys database for the remote user. If global host-key checking is enabled, the connection can be established only if the key that is sent matches an entry in the global host-keys database.
You can enforce strict host-key checking, global host-key checking, or both.
Important
Host keys are stored in the configuration database, so they are included in the backup file.
Note
The same scenario pertains to the primary and secondary Central Management System platforms in a Central Management System High-Availability (HA) deployment. In this case, the two Central Management System platforms exchange keys, and the connection is established if the keys match. For details, see the Central Management System High Availability Guide.
In compliance mode, both strict and global host-key checking is enforced. For details, see the FIPS 140-2 and Common Criteria Addendum.
For details, see the following topics:
Prerequisites
Admin access to configure authentication and create keys.
Monitor, Operator, or Admin access to obtain Central Management System appliance host keys.
The private key remains on the Network Security appliance and cannot be computed from the public key.
Obtaining a host key using the Web UI
Use the Certificate Management page to obtain the host key of the Central Management System appliance. This is the key that you will import into the global host-keys database of the managed Network Security appliance.
.png)
Note
This procedure applies to managed appliances running Release 7.6.0 or later. If the appliance is running an earlier release, see Obtaining a host key using the CLI .
Important
The host-key string may need to be modified in a Network Address Translation (NAT) deployment. For details, see Configuring global host-key authentication in a NAT deployment .
To obtain a host key:
Log in to the Central Management System Web UI.
Click the Settings tab.
Click Certificates/Keys on the sidebar.
Locate the Appliance Public Key string in the Keys section.
Copy the string starting with the IP address.
Do one of the following:
Paste the key into the managed NX CLI, as described in Importing a host key into the global host-keys database using the CLI.
Paste the key into the Central Management System Web UI, as described in Importing a host key into the global host-keys database using the Web UI.
Paste the key into a text file and save it for later.
Obtaining a host key using the CLI
Use the command in this section to obtain the host key of the Central Management System appliance. This is the key that you will import into the global host-keys database of the managed Network Security appliance.
Important
You must obtain the RSA v2 key.
The host-key string may need to be modified in Network Address Translation (NAT) deployments. For details, see Configuring global host-key authentication in a NAT deployment .
To obtain the host key:
Log in to the Central Management System CLI.
View the keys:
hostname > show ssh server host-keys interface ether1Locate the RSA v2 host key entry.
Do one of the following, depending on whether you will add the key using the Central Management System Web UI or CLI:
Web UI: Copy the key string, starting with the IP address and ending with the last character. Omit the double quotation marks at the beginning and end of the host key entry.
CLI: Copy the key string as described above, but include the double quotation marks.
Copy the key string, including the double quotation marks.
Do one of the following:
Paste the key into the Network Security CLI, as described in Importing a host key into the global host-keys database using the CLI .
Paste the key into a text file and save it for later.
Example
This example displays the Central Management System host keys. The RSA v2 key is highlighted for illustration.
CM-08 > show ssh server host-keys interface ether1SSH server configuration:
SSH server enabled: yes
.
.
.
Interface listen enabled: yes
Listen Interfaces:
Interface: ether1
Host Key Finger Prints and Key Lengths:
RSA v1 host key: 37:20:5f:af:65:33:e8:62:26:3c:25:d0:1f:2d:8a:54 (2048)
RSA v2 host key: c7:64:12:8a:71:a6:da:14:3c:05:37:aa:7a:2e:2a:8c (2048)
DSA v2 host key: 85:59:a8:a1:d8:3e:df:2e:74:fc:6a:be:be:d2:62:32 (1024)Host Keys:
RSA v1 host key: "10.11.121.13 2048 65537 2767892723557105143394492343612763
94200729942394341979526174787907308831935615818924165744283828800766510523178479
02037474895252247975570054315595358600142845914848782710493540937857691486699538
04205200729560274476403668156602030333253822356382587237819555941646603447324517
63747513796533041848893042157553987170029619742182277730552872281173097286794724
22744200184844597327452806661880313000836518022137675657765205670872217927843062
15703217249958957713631587970078908302914798758861955796169110420493384623007632
35665546051494669314340340626018765311569680255688151929860734984461083957535425
72032093143856912019598" RSA v2 host key: "10.11.121.13 ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDZZJLE/
ftkUddyNW6KdqEQXjS0PjbtzTn3OB51Qg0fdeQHrJgFHM2/4C9WtDkwuX5jd7gdWnSWYwrXDv657thly
RPIt4Wxjf0bpOolPKAe6shgYq35NxalYDt7Pa/oym51SN/x9dGaaTFOHvvdAf0Gu5E7nv3YjLjmSgdpS
p7auHnYsyJ5O+xlYocXtoBq6jOueyxm8qm76IWL007JIJ7ZLgMI8FjZ5gp48r+Hnjrdio2rhKKUP/6B0
jpHRxsd8yPxMgJpyz2Dwv9ZIJha67f6sgWYdt4yxfBc9yr7yG3iVWVJcLE+83aY24X7DBUXFnG3AeciD
pEqAit2dPF586hJ" DSA v2 host key: "10.11.121.13 ssh-dss AAAAB3NzaC1kc3MAAACBAMY7tSZt46Qrv/hqL
1tazYjXNzkyLTWp54DjfkxzE//+qjE0AUr9hTU3ZmHYChzUVTEKj7syaxd+4Y+8IZ94eRVcnrH/jrqtE
aJ64SvoUqGkbKKezUbCVfSrzGgTV/A0dUzLYMLbOEMrTMcXki+DnaUSd80PCWLvq0Mcg0IpXAAAAFQDI
tRIv/iH3AAy23h3cnWzp3dpOXQAAAIAS0AONTi0O8A+f1HNOm3PzS02ZQ9ittHxA1ISs7yE6dcbj9JrW
Vf1w2lJTEZAJPQz/c9NysGVJusll6Aj1aqQ6EKuhKlPcpY0PyCVKT3TGgY93i648umYZSs9+HzoLY1/a
TnnkBGDQ8mFbjhyw3UdeiFjamVVr+4o8QwMbDXAfXAAAAIEAjBMXsp4gK5yvsAgBqcZeZm3vW4zYUpZZ
374A3ANXENWTh2yyQd8Ig1gB0YKDBhSHD6sZpPg88WSDxK3IAdifYGx+FAhowiuWcI+kA0UeiAb9/C+A
653zii1Nc85/fsIwl3GIjmp/xO23b+9YmHY8V5CsT+mmSIYQutCIzUVWbcYvEc="
Importing a host key into the global host-keys database using the CLI
Use the commands in this section to import the host key from a Central Management System appliance into the Network Security appliance global host-keys database. This procedure is required for global host-key authentication, in which the connection will be allowed only if the host key the Central Management System sends is already in this database.
Caution
If you choose to use global host-key authentication, you must explicitly enable the feature in addition to importing the host key. For details, see Enabling strict and global host-key checking using the CLI.
Important
Before you perform this procedure, you must obtain the host key from the Central Management System appliance. You can obtain this key from the Central Management System Web UI or CLI. For details, see Obtaining a host key using the Web UI or Obtaining a host key using the CLI.
The host-key string may need to be modified in a Network Address Translation (NAT) deployment. For details, see Configuring global host-key authentication in a NAT deployment .
Note
See the
sshcommands in the CLI Command Reference for advanced authentication options.
To import a host key:
Log in to the Network Security CLI.
Go to CLI configuration mode:
hostname > enable hostname # configure terminalImport the key into the global host-keys database:
hostname (config) # ssh client global known-host "<keyString>"Important
The key must start with the managed appliance IP address, and it must be enclosed in double quotation marks. If the key starts with the hostname, replace the hostname with the IP address.
Verify your change:
Save your changes:
hostname (config) # write memory
To remove a host key:
Log in to the Network Security CLI.
Go to CLI configuration mode:
hostname > enable hostname # configure terminalRemove the key:
hostname (config) # no ssh client global known-host "<keyString>"Verify your change:
hostname (config) # show ssh server host-keysSave your changes:
hostname (config) # write memory
Caution
If you delete a host key that is in use, the connection between the Central Management System appliance and the managed appliance is broken.
Example
This example imports the host key from a Central Management System platform into the Network Security appliance global host-key database.
hostname (config) # ssh client global known-host "10.11.121.13 ssh-rsa AAAAB3
NzaC1yc2EAAAADAQABAAABAQDZZJLE/ftkUddyNW6KdqEQXjS0PjbtzTn3OB51Qg0fdeQHrJgFHM2
/4C9WtDkwuX5jd7gdWnSWYwrXDv657thlyRPIt4Wxjf0bpOolPKAe6shgYq35NxalYDt7Pa/oym51
SN/x9dGaaTFOHvvdAf0Gu5E7nv3YjLjmSgdpSp7auHnYsyJ5O+xlYocXtoBq6jOueyxm8qm76IWL0
07JIJ7ZLgMI8FjZ5gp48r+Hnjrdio2rhKKUP/6B0jpHRxsd8yPxMgJpyz2Dwv9ZIJha67f6sgWYdt
4yxfBc9yr7yG3iVWVJcLE+83aY24X7DBUXFnG3AeciDpEqAit2dPF586hJ"
hostname (config) # show ssh server host-keys
SSH client Strict Hostkey Checking: ask
Minimum protocol version: 2
Cipher list: compatible
Minimum key length: 1024 bits
SSH Global Known Hosts:
Entry 1:
Host: 10.11.121.13
Finger Print: c7:64:12:8a:71:a6:da:14:3c:05:37:aa:7a:2e:2a:8c
Key Length (bits): 2048
...Enabling strict and global host-key checking using the CLI
Use the commands in this section to enable strict host-key checking, global host-key checking, or both.
With strict host-key checking, the connection will be allowed only if the local host-keys database for the remote user already has an entry that matches the key the Central Management System appliance sends.
With global host-key checking, the connection will be allowed only if the global Network Security host-keys database already has an entry that matches the key the Central Management System appliance sends.
Caution
When you enable global host-key authentication, any established connections will be broken until you explicitly add the host key to the global host-keys database. See Importing a global host key using the CLI for instructions.
Note
See the
sshandcmccommands in the CLI Command Reference for advanced authentication options.
To enable strict host-key checking:
Log in to the Network Security CLI.
Go to CLI configuration mode:
hostname > enable hostname # configure terminalEnable strict host-key checking:
hostname (config) # cmc auth ssh host-key strictVerify your changes:
hostname (config) # show cmc auth sshSave your changes:
hostname (config) # write memory
To enable global host-key checking:
Log in to the Network Security CLI.
Go to CLI configuration mode:
hostname > enable hostname # configure terminalEnable global host-key checking:
hostname (config) # cmc auth ssh host-key global-onlyVerify your changes:
hostname (config) # show cmc auth sshSave your changes:
hostname (config) # write memory
To disable strict or global host-key authentication:
Log in to the CLI.
Go to CLI configuration mode:
hostname > enable hostname # configure terminalPerform the following steps as needed.
To disable strict host-key checking:
hostname (config) # no cmc auth ssh host-key strictTo disable global host-key checking:
hostname (config) # no cmc auth ssh host-key global
Verify your changes:
hostname (config) # show cmc auth sshSave your changes:
hostname (config) # write memory
Example
This example enforces both strict and global host-key checking on a managed Network Security appliance.
hostname (config) # cmc auth ssh host-key strict
hostname (config) # cmc auth ssh host-key global-only
hostname (config) # show cmc auth ssh
CMC SSH configuration:
Strict host key checking enabled: yes
Global only known hosts enabled: yes
Minimum protocol version: 2
Cipher list: compatible
Minimum key length: 1024 bits