我司交换机默认的算法如下:
Key exchange algorithms: ecdh-sha2-nistp256 ecdh-sha2-nistp384 dh-group-exchange-sha1 dh-group14-sha1 dh-group1-sha1
Public key algorithms: x509v3-ecdsa-sha2-nistp256 x509v3-ecdsa-sha2-nistp384 ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 rsa dsa
Encryption algorithms: aes128-ctr aes192-ctr aes256-ctr aes128-gcm aes256-gcm aes128-cbc 3des-cbc aes256-cbc des-cbc
MAC algorithms: sha2-256 sha2-512 sha1 md5 sha1-96 md5-96
客户处将禁用公钥算法里的RSA和dsa,但是禁用后,出现crt无法ssh远程登录设备的问题,通过其他交换机远程提示秘钥不匹配的提示,但是吧另外一台网络设备也禁用公钥算法中的RSA和DSA仍然提示秘钥不匹配,这种问题要使CRT和其他交换机也可以远程登录要怎么操作。
m.163.com/news/rec/YDJ0477U9IO31XWW.html
m.163.com/news/rec/YDJ0967U9IO2UWZY.html
m.163.com/news/rec/YDJ0877U9IO2KXZY.html
m.163.com/news/rec/YDJ0617U9IO2VXYX.html
m.163.com/news/rec/YDJ0787U9IO2QWWW.html
m.163.com/news/rec/YDJ0057U9IO2HWXW.html
m.163.com/news/rec/YDJ1267U9IO2PYWZ.html
m.163.com/news/rec/YDJ0737U9IO1MYWX.html
m.163.com/news/rec/YDJ0227U9IO2TZWY.html
m.163.com/news/rec/YDJ0047U9IO2RYXW.html
m.163.com/news/rec/YDJ0657U9IO1QYYZ.html
m.163.com/news/rec/YDJ1137U9IO2OXXX.html
m.163.com/news/rec/YDJ1157U9IO2NWWX.html
m.163.com/news/rec/YDJ0937U9IO2IYXW.html
m.163.com/news/rec/YDJ1277U9IO1CWZW.html
m.163.com/news/rec/YDJ0627U9IO2CZXZ.html
m.163.com/news/rec/YDJ0047U9IO2GXXZ.html
m.163.com/news/rec/YDJ0847U9IO2FYWY.html
m.163.com/news/rec/YDJ0147U9IO2DWZY.html
m.163.com/news/rec/YDJ0327U9IO29WZX.html
m.163.com/news/rec/YDJ0147U9IO2AXZZ.html
m.163.com/news/rec/YDJ0717U9IO2EXWZ.html
m.163.com/news/rec/YDJ0487U9IO2BYZW.html
m.163.com/news/rec/YDJ0687U9IO24ZXZ.html
m.163.com/news/rec/YDJ0827U9IO23ZWY.html
m.163.com/news/rec/YDJ0757U9IO28ZZZ.html
m.163.com/news/rec/YDJ0287U9IO27ZWZ.html
m.163.com/news/rec/YDJ1187U9IO21WWX.html
m.163.com/news/rec/YDJ0667U9IO26XXY.html
m.163.com/news/rec/YDJ0257U9IO22WWW.html
m.163.com/news/rec/YDJ0077U9IO20YYY.html
m.163.com/news/rec/YDJ0647U9IO1UWXX.html
m.163.com/news/rec/YDJ1237U9IO1SXWY.html
m.163.com/news/rec/YDJ0937U9IO1TWZX.html
m.163.com/news/rec/YDJ0217U9IO1RYYX.html
m.163.com/news/rec/YDJ1137U9IO1VWXY.html
m.163.com/news/rec/YDJ0107U9IO1NXZZ.html
m.163.com/news/rec/YDJ0357U9IO1LXWX.html
m.163.com/news/rec/YDJ0267U9IO1KYZY.html
m.163.com/news/rec/YDJ0767U9IO1PZYX.html
m.163.com/news/rec/YDJ0777U9IO1FWZY.html
m.163.com/news/rec/YDJ0187U9IO1OZZY.html
m.163.com/news/rec/YDJ0087U9IO1JWZZ.html
m.163.com/news/rec/YDJ0627U9IO1GYZY.html
m.163.com/news/rec/YDJ0507U9IO1IYYY.html
m.163.com/news/rec/YDJ1057U9IO1HYYY.html
m.163.com/news/rec/YDJ0327U9IO1EZXW.html
m.163.com/news/rec/YDJ1007U9IO1DYYX.html
m.163.com/news/rec/YDJ0537U9IO1BWXZ.html
m.163.com/news/rec/YDJ0617U9INUOZZW.html
m.163.com/news/rec/YDJ0937U9INVNYYY.html
m.163.com/news/rec/YDJ0247U9IO1AYXZ.html
m.163.com/news/rec/YDJ0277U9IO16XWX.html
m.163.com/news/rec/YDJ0377U9IO17ZWX.html
m.163.com/news/rec/YDJ0207U9IO19XXX.html
m.163.com/news/rec/YDJ0977U9IO15WZY.html
m.163.com/news/rec/YDJ0907U9IO18YXX.html
m.163.com/news/rec/YDJ0617U9IO0OWXX.html
m.163.com/news/rec/YDJ0937U9IO13YYY.html
m.163.com/news/rec/YDJ0477U9IO0QZWZ.html
m.163.com/news/rec/YDJ0787U9IO0LYYZ.html
m.163.com/news/rec/YDJ0877U9IO12WXZ.html
m.163.com/news/rec/YDJ0357U9INVTYZZ.html
m.163.com/news/rec/YDJ0967U9IO0NXXW.html
m.163.com/news/rec/YDJ0227U9IO0MZWY.html
m.163.com/news/rec/YDJ1137U9IO0JYWW.html
m.163.com/news/rec/YDJ0877U9IO0HWXX.html
m.163.com/news/rec/YDJ1157U9IO0FYWW.html
m.163.com/news/rec/YDJ0627U9IO07XZZ.html
m.163.com/news/rec/YDJ0057U9IO09ZXZ.html
m.163.com/news/rec/YDJ0007U9IO0EYWZ.html
m.163.com/news/rec/YDJ0047U9IO0DZZZ.html
m.163.com/news/rec/YDJ0937U9IO0GXXY.html
m.163.com/news/rec/YDJ1267U9IO0BXYW.html
m.163.com/news/rec/YDJ0847U9IO0CYZY.html
m.163.com/news/rec/YDJ0717U9IO03ZWX.html
m.163.com/news/rec/YDJ0327U9IO0AYZX.html
m.163.com/news/rec/YDJ0487U9IO04ZZZ.html
m.163.com/news/rec/YDJ0667U9IO06WZZ.html
m.163.com/news/rec/YDJ0147U9IO08YWW.html
m.163.com/news/rec/YDJ0647U9INVMXYW.html
m.163.com/news/rec/YDJ0757U9IO05WZZ.html
m.163.com/news/rec/YDJ0687U9IO02ZXW.html
m.163.com/news/rec/YDJ0827U9IO01XYZ.html
m.163.com/news/rec/YDJ0847U9INU7XWZ.html
m.163.com/news/rec/YDJ0147U9INVGXWX.html
m.163.com/news/rec/YDJ0257U9IO00XZZ.html
m.163.com/news/rec/YDJ0277U9INV1WWZ.html
m.163.com/news/rec/YDJ1137U9INVQYXW.html
m.163.com/news/rec/YDJ0077U9INVVYZZ.html
m.163.com/news/rec/YDJ0107U9INVUWYY.html
m.163.com/news/rec/YDJ1187U9INVPZWX.html
m.163.com/news/rec/YDJ1237U9INVKXYW.html
m.163.com/news/rec/YDJ0657U9INVOWWY.html
m.163.com/news/rec/YDJ0217U9INVRYYW.html
m.163.com/news/rec/YDJ0187U9INVSWZX.html
m.163.com/news/rec/YDJ0737U9INVJXXW.html
m.163.com/news/rec/YDJ0767U9INVLXZY.html
m.163.com/news/rec/YDJ0267U9INVIYWW.html
m.163.com/news/rec/YDJ0777U9INVEYZX.html
m.163.com/news/rec/YDJ0507U9INVDWWX.html
m.163.com/news/rec/YDJ0627U9INVHYWZ.html
m.163.com/news/rec/YDJ0087U9INVCWYW.html
m.163.com/news/rec/YDJ0047U9INVFXYY.html
m.163.com/news/rec/YDJ1277U9INV9XZY.html
m.163.com/news/rec/YDJ0207U9INVBWWY.html
m.163.com/news/rec/YDJ1057U9INV2ZWW.html
m.163.com/news/rec/YDJ0537U9INV8XXZ.html
m.163.com/news/rec/YDJ0247U9INV3ZYY.html
m.163.com/news/rec/YDJ0327U9INVAYYY.html
m.163.com/news/rec/YDJ0377U9INV6YWX.html
m.163.com/news/rec/YDJ1007U9INV5WZZ.html
m.163.com/news/rec/YDJ0907U9INV7ZYZ.html
m.163.com/news/rec/YDJ0047U9INV4XXW.html
m.163.com/news/rec/YDJ0287U9INUVYXY.html
m.163.com/news/rec/YDJ0977U9INV0YXY.html
m.163.com/news/rec/YDJ0937U9INUTZWX.html
m.163.com/news/rec/YDJ0477U9INUPYZZ.html
m.163.com/news/rec/YDJ0007U9INUGYXZ.html
m.163.com/news/rec/YDJ0717U9INTUZYW.html
m.163.com/news/rec/YDJ0877U9INUUZZZ.html
m.163.com/news/rec/YDJ0967U9INUEZXY.html
m.163.com/news/rec/YDJ1137U9INUKWZW.html
m.163.com/news/rec/YDJ0227U9INUMWXZ.html
m.163.com/news/rec/YDJ0877U9INUIXXX.html
m.163.com/news/rec/YDJ0937U9INUHZWX.html
m.163.com/news/rec/YDJ1157U9INUFYXY.html
m.163.com/news/rec/YDJ0667U9INU9XWX.html
m.163.com/news/rec/YDJ0327U9INUBXYW.html
m.163.com/news/rec/YDJ1267U9INUCXYY.html
m.163.com/news/rec/YDJ0627U9INU8ZWW.html
m.163.com/news/rec/YDJ0757U9INUAWXY.html
m.163.com/news/rec/YDJ0147U9INU6WXY.html
m.163.com/news/rec/YDJ0257U9INU2ZXZ.html
m.163.com/news/rec/YDJ0687U9INU5YZW.html
m.163.com/news/rec/YDJ0077U9INU1ZZY.html
m.163.com/news/rec/YDJ0057U9INU0YYW.html
m.163.com/news/rec/YDJ0647U9INTPYYZ.html
m.163.com/news/rec/YDJ0487U9INU3ZZY.html
m.163.com/news/rec/YDJ0107U9INTRXYW.html
m.163.com/news/rec/YDJ0187U9INU4ZWX.html
m.163.com/news/rec/YDJ0147U9INTJXYY.html
m.163.com/news/rec/YDJ0767U9INTNXWW.html
m.163.com/news/rec/YDJ0787U9INTTWWX.html
m.163.com/news/rec/YDJ0627U9INTLWXY.html
m.163.com/news/rec/YDJ1137U9INTFXZY.html
m.163.com/news/rec/YDJ0357U9INTMYWX.html
m.163.com/news/rec/YDJ1187U9INTVZWZ.html
m.163.com/news/rec/YDJ0937U9INTOWZX.html
m.163.com/news/rec/YDJ0657U9INTQYXW.html
m.163.com/news/rec/YDJ1237U9INTSXWY.html
m.163.com/news/rec/YDJ0737U9INTKWXX.html
m.163.com/news/rec/YDJ0507U9INTIXXW.html
m.163.com/news/rec/YDJ0207U9INTEXZY.html
m.163.com/news/rec/YDJ0217U9INTHZWW.html
m.163.com/news/rec/YDJ0537U9INTDZYW.html
m.163.com/news/rec/YDJ0377U9INSTWWY.html
m.163.com/news/rec/YDJ0277U9INT4ZZX.html
m.163.com/news/rec/YDJ1277U9INTBWXZ.html
m.163.com/news/rec/YDJ0267U9INTGYXW.html
m.163.com/news/rec/YDJ0047U9INT8ZYW.html
m.163.com/news/rec/YDJ0047U9INTAWWZ.html
m.163.com/news/rec/YDJ0087U9INTCZZY.html
m.163.com/news/rec/YDJ0047U9INT2ZXW.html
m.163.com/news/rec/YDJ0247U9INT9ZXW.html
m.163.com/news/rec/YDJ0327U9INT7XXW.html
m.163.com/news/rec/YDJ1007U9INT6YXW.html
m.163.com/news/rec/YDJ0287U9INT0YZW.html
m.163.com/news/rec/YDJ1057U9INSSYXW.html
m.163.com/news/rec/YDJ0777U9INT5XZX.html
m.163.com/news/rec/YDJ0937U9INSUZWW.html
m.163.com/news/rec/YDJ0907U9INT3ZXX.html
m.163.com/news/rec/YDJ0877U9INT1XZW.html
m.163.com/news/rec/YDJ0977U9INSVWYZ.html
要解决禁用 RSA/DSA 公钥算法后 SSH 无法登录的问题,关键在于确保 SSH 客户端主动选择 ECDSA 算法,并且 交换机已正确生成 ECDSA 主机密钥。
禁用 RSA/DSA 后,交换机必须使用 ECDSA 密钥作为主机身份证明。
检查:display public-key local ecdsa public
如果没有或需要重新生成:
undo ssh server enable 后再 ssh server enable。关键:清除旧的 RSA 主机密钥缓存,并强制使用 ECDSA 算法。
修改会话算法:
右键点击会话 → Properties → SSH2 选项卡:
Key Exchange:确保列表包含 ecdh-sha2-nistp256、ecdh-sha2-nistp384,可移除 diffie-hellman 开头的选项。
Authentication:Public Key 部分,选择 Use session public key setting。
Advanced:勾选 Use ECDH key exchange for ECDSA keys(如有此选项)。
保存后重试连接。
当从交换机 A SSH 登录到交换机 B 时,需在命令中显式指定使用 ECDSA 主机密钥验证。
在 PuTTY 的 Connection → SSH → Auth 中,确保 Host keys 勾选 ecdsa-sha2-nistp256、ecdsa-sha2-nistp384。
在 Connection → SSH → Kex 中,优先选择 ecdh-sha2-nistp256 等 ECDH 算法。
删除已保存的旧主机密钥(通过注册表或 PuTTY 的 Host Keys 管理)。
在交换机上开启 SSH 调试信息,观察客户端协商的算法:
ecdsa-sha2-nistp256。SecureCRT:连接时会在 Log 窗口显示“The server supports the following host key algorithms: ...”,检查其中是否包含 ECDSA。
交换机客户端:使用 -v 参数查看详细调试信息(部分型号支持)。
仍报“密钥不匹配”:100% 是因为客户端缓存了旧的 RSA 主机公钥,必须彻底删除。
连接被拒绝:可能是服务端未生成 ECDSA 密钥,或 ssh2 algorithm public-key 配置错误(如遗漏 ECDSA 算法)。
连接超时:检查网络连通性及 SSH 服务端口(默认 22)。
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论