User Manual

IP Establishing Sessions
6-12
6.5.2.3 Username/Password Authentication
If RSA authentication fails, the SCS prompts the user for a password. The user’s name and password are
then checked against the Kerberos, TFTP, and Local authentication databases, in order of their precedence
settings if configured.
Figure 6-28: Username/Password Authentication
Note: The RADIUS and SecurID databases will not be checked. Also, expired local
passwords cannot be updated and login scripts will not be run at this point of the
SSH process.
Once the username and password are verified, SSH authentication is complete. The user will be moved on
to any previously configured user authentication (as enabled with the Set/Define Ports Authenticate
command) that would normally apply to a login on that port. At this point, all authentication methods,
including RADIUS and SecurID, will be available, and expired local passwords will be prompted for
updates.
For example, if authentication is enabled on virtual ports (port 0), the user in Figure 6-29 will be prompted
again for the username and password.
Figure 6-29: Previously Configured User Authentication
6.5.2.4 Outgoing SSH Connections
Note: RSA user authentication is not available for outgoing SSH connections.
To form an SSH connection to another host from the SCS, enter the ssh command followed by the desired
host’s hostname or IP address.
The first time you SSH to a remote host from the SCS, the SCS notes that the host is not recognized, but
permits the connection. If you are not the privileged user, you will be allowed to use the host’s key for the
current session, but the key will not be permanently saved in the list of known hosts.
Figure 6-30: Outgoing SSH Connections for Nonprivileged User
% ssh scs2
paul@scs2's password:
% ssh scs2
paul@scs2's password:(not echoed)
Lantronix Version n.n/n (yymmdd)
Type Help at the ‘Local_>’ prompt for assistance.
Username> paul
Password> (not echoed)
Local_9> ssh athena
%Info: The authenticity of host ‘athena’ can't be established.
RSA key fingerprint is 5f:d0:d7:69:39:d1:ca:fb:71:eb:g4:33:b1:ba:8c:e9.
%Warning: Failed to add the host to the list of known hosts
/flash/ssh/known_hosts: Permission denied
mary@athena's password: