Cisco Systems OL-5650-02 Switch User Manual


 
CHAPTER
2-1
Cisco Content Services Switch Security Configuration Guide
OL-5650-02
2
Configuring the Secure Shell Daemon
Protocol
The Secure Shell Daemon (SSHD) protocol provides secure encrypted
communications between two hosts communicating over an insecure network.
The CSS supports an implementation of OpenSSH to provide this secure
communication. SSHD uses the standard CSS login sequence of entering the
username and password at the CSS login prompts.
SSHD on the CSS supports both the SSH v1 and v2 protocols. For SSH v1, the
software provides encrypted communication using ciphers such as 3DES or
Blowfish. For SSH v2, the software provides 128-bit AES, Blowfish, 3DES,
CAST128, Arcfour, 192-bit AES, or 256-bit AES.
Caution When using SSHD, ensure that the CSS is not configured to perform a network
boot from a network-mounted file system on a remote system (a diskless
environment). If you require the CSS to use the network-mounted method of
booting, be aware that the SSHD protocol is not supported.
If the CSS has been booted using a network boot from a network-mounted file
system, the CSS logs the following error message by SSHD as the protocol
attempts to initialize (and then exit from operation):
Unable to initialize sshd; failure to seed random number generator