{"id":2516,"date":"2009-10-05T22:41:13","date_gmt":"2009-10-05T20:41:13","guid":{"rendered":"http:\/\/security-planet.de\/?p=2516"},"modified":"2009-10-05T22:41:13","modified_gmt":"2009-10-05T20:41:13","slug":"cisco-ios-public-key-basierte-logins","status":"publish","type":"post","link":"https:\/\/cyber-fi.net\/index.php\/2009\/10\/05\/cisco-ios-public-key-basierte-logins\/","title":{"rendered":"Cisco IOS: Public-Key-basierte SSH-Logins"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.iwen.de\/wp-content\/uploads\/2008\/12\/router.png\" alt=\"router\" title=\"router\" width=\"70\" height=\"49\" class=\"alignleft size-full wp-image-643\" \/>Ein lang gehegter Wunsch ist mit IOS 15.0 in Erf\u00fcllung gegangen. SSH-Logins mit Public-Key-Authentifizierung:<\/p>\n<blockquote><p>\n<a href=\"http:\/\/www.cisco.com\/en\/US\/docs\/ios\/sec_user_services\/configuration\/guide\/sec_secure_shell_v2.html#wp1063190\">http:\/\/www.cisco.com\/en\/US\/docs\/ios\/sec_user_services\/configuration\/guide\/sec_secure_shell_v2.html#wp1063190<\/a><\/p><\/blockquote>\n<p>Leider klappt es bei mir noch nicht &#8230; \ud83d\ude41<\/p>\n<p><strong>Update 06.10.09:<\/strong> Nach anf\u00e4nglichen Schwierigkeiten l\u00e4uft es jetzt. Es hat nicht funktioniert, solange ich den Befehl<\/p>\n<pre class><code>aaa authorization exec default local<\/code><\/pre>\n<p>in der Konfiguration hatte, um beim Login direkt im Enable-Mode zu landen. Ohne Exec-Authorization hat man aber leider nicht die M\u00f6glichkeit, verschiedene User in unterschiedliche Level einloggen zu lassen. Der Wechsel in den Level15 klappt aber mit der direkten Konfiguration auf der vty-Line:<\/p>\n<pre class><code>line vty 0 4\n privilege level 15<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Ein lang gehegter Wunsch ist mit IOS 15.0 in Erf\u00fcllung gegangen. SSH-Logins mit Public-Key-Authentifizierung: http:\/\/www.cisco.com\/en\/US\/docs\/ios\/sec_user_services\/configuration\/guide\/sec_secure_shell_v2.html#wp1063190 Leider klappt es bei mir noch nicht &#8230; \ud83d\ude41 Update 06.10.09: Nach anf\u00e4nglichen Schwierigkeiten l\u00e4uft es jetzt. Es hat nicht funktioniert, solange ich den Befehl aaa authorization exec default local in der Konfiguration hatte, um beim Login direkt im Enable-Mode <\/p>\n<div class=\"read-more-text\"><a href=\"https:\/\/cyber-fi.net\/index.php\/2009\/10\/05\/cisco-ios-public-key-basierte-logins\/\" class=\"read-more\">continue reading<\/a><\/div>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[5],"tags":[307,573],"class_list":["post-2516","post","type-post","status-publish","format-standard","hentry","category-cisco","tag-ios","tag-ssh"],"_links":{"self":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/2516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/comments?post=2516"}],"version-history":[{"count":0,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/2516\/revisions"}],"wp:attachment":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/media?parent=2516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/categories?post=2516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/tags?post=2516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}