4 ms·
There are not many network vendors. Check the link in the first footnote for an example how Cisco, the leader in the field, makes it difficult to deploy SSH key
by vbernat 3y ago
There are not many network vendors. Check the link in the first footnote for an example how Cisco, the leader in the field, makes it difficult to deploy SSH keys. This is getting better. For example, Juniper (another network vendor) now supports SSH certificates.
- RedShift1 3y agoI have no idea what's going on in the footnote, but deploying SSH keys on Cisco equipment is like 3 commands (conf t, user x, ssh something something) to deploy public keys, not hard at all.
- vbernat 3y agoNot on IOS XR: https://vincent.bernat.ch/en/blog/2020-syncing-ssh-keys-iosxr-ansible#how-to-add-an-ssh-key-to-a-user https://vincent.bernat.ch/en/blog/2020-syncing-ssh-keys-iosx.... The commands you mention are for NXOS.
- bnny 3y agoIt's been a few years, but this requires manually deploying keys and adding/removing users on all your devices. Most use TACACS+ and/or Radius to centrally manage users, which don't support keys in that way (or at least didn't the last time I worked with them.)
- vbernat 3y agoThere is an implementation with an extension: https://github.com/MarcJHuber/event-driven-servers/wiki/TACACS_PLUS---SSH-Public-Key-Authentication https://github.com/MarcJHuber/event-driven-servers/wiki/TACA.... But I don't know if there are any supported clients. Another possibility would be to use CA certificates for authentication and only TACACS+ for authorization and accounting. Juniper now supports CA certificates. Cisco may in 10 years.