SSH key-based authentication for local system users
To have a secured user access for the NetScaler appliance you can have the public key authentication of the SSH server. The SSH key-based authentication is preferred over traditional user name or password based authentication for the following reasons:
-
Provides better cryptographic strength than user passwords.
-
Eliminates the need of remembering complicated passwords and prevents shoulder-surfing attacks which are possible if passwords are used.
-
Provides a password-less login for making automation scenarios more secured.
NetScaler supports SSH key-based authentication by applying the public and private key concept. The SSH key-based authentication in NetScaler can be enabled either for a specific user or for all local users.
Note
The feature is supported only for NetScaler local users and not supported for external users.
SSH key-based authentication for local system users
In a NetScaler appliance, an administrator can set up SSH key-based authentication for a secured system access. When a user logs into the NetScaler using a private key, the system authenticates the user using the public key configured on the appliance.
Configure SSH key-based authentication for the NetScaler local system users by using CLI
Following configuration helps you to configure key-based authentication for NetScaler local system users.
-
Log on to a NetScaler appliance using administrator credentials.
-
By default your
sshd_configfile accesses this path: AuthorizedKeysFile /nsconfig/ssh/authorized_keys. -
Append the public key to the authorized_keys file: /nsconfig/ssh/authorized_keys. The file path for
sshd_configis/etc/sshd_config. -
Copy the
sshd_configfile into/nsconfigto ensure that the changes persist even after restarting the appliance. -
You can use the following command to restart your
sshdprocess.
kill -HUP `cat /var/run/sshd.pid`
Note
If the authorized_keys file is not available, you must first create one and then append the public key. Make sure the file has the following permission for the authorized_keys.
root@NetScaler# chmod 0644 authorized_keys
> shell
Copyright (c) 1992-2013 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
root@ns# cd /nsconfig/ssh
root@ns# vi authorized_keys
### Add public keys in authorized_keys file
User-specific SSH key-based authentication for local system users
In a NetScaler appliance, an administrator can now set up a user specific SSH key-based authentication for a secured system access. The administrator must first configure the
Authorizedkeysfile option in the sshd_config file and then add the public key in the authorized_keys file for a system user.
Note
If the authorized_keys file is not available for a user, the administrator must first create one and then add the public key to it.
Configure user-specific SSH key-based authentication by using the CLI
Following procedure helps you to configure user-specific SSH key-based authentication for NetScaler local system users.
-
Log on to a NetScaler appliance using administrator credentials.
-
At the shell prompt, access the
sshd_configfile and add the following configuration line:AuthorizedKeysFile ~/.ssh/authorized_keysNoteThe ~ is the home directory and differs for different users. It expands to the different home directory. -
Change the directory to the system user folder and add the public keys in the
authorized_keysfile./var/pubkey/<username>/.ssh/authorized_keys
Once you have completed the earlier steps, restart the
sshd process on your appliance by the following command:
kill -HUP `cat /var/run/sshd.pid`
Note
If the authorized_keys file is not available, you must first create one and then add the public key.
> shell
Copyright (c) 1992-2013 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
root@ns# cd /var/pubkey/<username>/
root@ns# ls
.ssh
root@ns# cd .ssh
root@ns# vi authorized_keys
### Add public keys in authorized_keys file
Also, read Citrix article, CTX109011 to know how secure SSH access to NetScaler appliance works.