{"componentChunkName":"component---src-templates-manual-template-tsx","path":"/manuals/client-user/44/Examples.html","webpackCompilationHash":"d1750f6cc413894a8b5c","result":{"data":{"promoBlocks":{"edges":[{"node":{"contentful_id":"47glnSpWzXeFylv2vfQEF8","internal":{"type":"ContentfulPromotionBlock"},"title":{"internal":{"type":"ContentfulHeading"},"contentful_id":"7KIOfSfgwJnCXuvRN6CfrP","textContent":"Standing privileges are a risk with PAM","color":"black","size":"medium"},"subTitle":null,"content":{"nodeType":"document","internal":{"content":"{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"content\":[{\"nodeType\":\"text\",\"value\":\"Start your journey towards a just-in-time (JIT) model with zero standing privileges (ZSP). Read 'Remove Standing Privileges Through a Just-In-Time PAM Approach' by Gartner , courtesy of SSH.COM.\\n \\n\",\"marks\":[],\"data\":{}}],\"data\":{}}]}"}},"callToAction":{"internal":{"type":"ContentfulButton"},"contentful_id":"19EUesynV2Z7HHcuJk0BAS","content":"Download Gartner research","internalLink":null,"externalLink":"https://info.ssh.com/gartner_research_privileged_access_management","assetLink":null,"anchor":null},"picture":{"internal":{"type":"ContentfulAsset"},"contentful_id":"2ClylmBswcfDx4XdO7NTmL","title":"ICON Gartner ZSP","description":"","file":{"url":"//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png","contentType":"image/png"},"fluid":{"aspectRatio":1,"src":"//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png?w=3000&q=50","srcSet":"//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png?w=750&h=750&q=50 750w,\n//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png?w=1500&h=1500&q=50 1500w,\n//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png?w=1601&h=1601&q=50 1601w","sizes":"(max-width: 3000px) 100vw, 3000px"},"fixed":{"width":3000,"height":3000,"src":"//images.ctfassets.net/0lvk5dbamxpi/2ClylmBswcfDx4XdO7NTmL/78e899153ed66aec3b03b9a2cacd112d/ICON_Gartner_ZSP_ICON_Gartner.png?w=3000&q=50","srcSet":""}},"centered":true,"indentMainContent":null,"transparentBackground":null,"imageScale":70,"imagePadding":null,"name":"WIKI migration side promo block2","product":null,"funnel":null,"topic":null,"keywords":null,"type":null,"priority":null,"globalOverride":null}},{"node":{"contentful_id":"6dfNaA1UlY4bADKQk6awhs","internal":{"type":"ContentfulPromotionBlock"},"title":{"internal":{"type":"ContentfulHeading"},"contentful_id":"49Tb2wSR21P5C2cpcgMZ3","textContent":"Get Multi-cloud PAM software - for free!","color":"black","size":"medium"},"subTitle":null,"content":{"nodeType":"document","internal":{"content":"{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"PrivX® Free replaces your in-house jump hosts and combines your AWS, GCP and Azure access into one multi-cloud solution.\\n \\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"}"}},"callToAction":{"internal":{"type":"ContentfulButton"},"contentful_id":"1dmQ13jyyZ46ID07eVNVFb","content":"PrivX Free","internalLink":null,"externalLink":"https://info.ssh.com/privx-free-access-management-software","assetLink":null,"anchor":null},"picture":{"internal":{"type":"ContentfulAsset"},"contentful_id":"4UUYdjING8micwZQur5o6d","title":"ICON computer (search)","description":"","file":{"url":"//images.ctfassets.net/0lvk5dbamxpi/4UUYdjING8micwZQur5o6d/1b378a0f4646075c7a4788f1afffbabe/ICON_computer__search_.svg","contentType":"image/svg+xml"},"fluid":{"aspectRatio":null,"src":null,"srcSet":null,"sizes":null},"fixed":{"width":null,"height":null,"src":null,"srcSet":null}},"centered":true,"indentMainContent":null,"transparentBackground":null,"imageScale":70,"imagePadding":null,"name":"WIKI migration side promo block1","product":null,"funnel":null,"topic":null,"keywords":null,"type":null,"priority":null,"globalOverride":null}}]}},"pageContext":{"isCreatedByStatefulCreatePages":false,"body":"<div text=\"#303030\" vLink=\"#006a6e\" aLink=\"#006a6e\" link=\"#006a6e\" bgColor=\"#ffffff\" leftMargin=\"0\" topMargin=\"0\" marginheight=\"0\" marginwidth=\"0\">\n\n<!-- header -->\n<table width=\"100%\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\" class=\"header\">\n  <tbody><tr bgColor=\"#006a6e\" valign=\"top\">\n    <td width=\"324\"><A href=\"http://www.ssh.com/\"><img src=\"gfx/header_logo.gif\" alt=\"SSH Tectia\" width=\"324\" height=\"44\" border=\"0\"></td>\n    <td width=\"451\">\n      <!-- tools -->\n      &nbsp;\n      <!-- /tools -->\n    </td>\n    <td width=\"100%\"><img src=\"gfx/1x1.gif\" width=\"10\" height=\"1\" alt=\"\" border=\"0\"></td>\n  </tr></tbody>\n</table>\n<!-- /header -->\n\n<!-- navi level 1 -->\n<table width=\"100%\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n  <tbody><tr valign=\"top\">\n    <td width=\"178\"><img src=\"gfx/navi1_left.gif\" alt=\"\" width=\"178\" height=\"26\" border=\"0\"></td>\n\n    <td width=\"100%\">\n      <table width=\"100%\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n        <tbody><tr>\n          <td width=\"100%\" bgcolor=\"#1a797d\" background=\"gfx/navi1_bg.gif\"><img src=\"gfx/1x1.gif\" height=\"26\" alt=\"\" border=\"0\"></td>\n        </tr></tbody>\n      </table>\n    </td>\n  </tr></tbody>\n</table>\n<!-- /navi level 1 -->\n\n<!-- navi level 2 -->\n<img src=\"gfx/1x1.gif\" width=\"1\" height=\"5\" alt=\"\" border=\"0\">\n\n<table cellspacing=\"0\" cellpadding=\"0\" width=\"740\" border=\"0\">\n<tr>\n<td width=\"540\">\n</tr>\n<!-- /navi level 2 -->\n\n<IMG height=\"21\" alt=\"\" src=\"gfx/1x1.gif\" width=\"1\" border=\"0\" > \n\n<TABLE cellSpacing=\"0\" cellPadding=\"0\" width=\"100%\" border=\"0\" >\n  <TBODY>\n  <TR valign=\"top\">\n    <TD width=\"99\"><IMG height=\"1\" alt=\"\" src=\"gfx/1x1.gif\" width=\"99\" border=\"0\" ></TD>\n    <TD width=\"90%\">\n        <TABLE cellSpacing=\"0\" cellPadding=\"0\" width=\"100%\" border=\"0\" >\n        <TBODY>\n        <TR valign=\"top\">\n          <TD width=\"100%\">\n<!-- main column -->\n\n<font face=\"Arial,Helvetica,sans-serif\">\n<table width=\"100%\"><tr><td valign=\"bottom\"><a href=\"Options-5.html\"><img align=\"center\" border=\"0\" src=\"gfx/prev.gif\" alt=\"Previous\"></a>\n<a href=\"ssh-certview.html\"><img align=\"center\" border=\"0\" src=\"gfx/next.gif\" alt=\"Next\"></a>\n<a href=\"ssh-cmpclient.html\"><img align=\"center\" border=\"0\" src=\"gfx/up.gif\" alt=\"Up\"></a>\n<font face=\"Arial,Helvetica,sans-serif\" size=\"2\">[<a href=\"index.html\">Contents</a>]\n[<a href=\"index-25.html\">Index</a>]\n</font></td><td align=\"right\"></td></tr></table>\n<p>\n<table align=\"right\" cellpadding=\"5\"cellspacing=\"5\"><tr><td bgcolor=\"#C3DBDD\"><font face=\"Arial,Helvetica,sans-serif\" size=\"-2\">\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"About_This_Document.html\">About This Document</a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Installing_SSH_Tectia_Client.html\">Installing SSH Tectia Client </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"getting_started.html\">Getting Started </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"configuration.html\">Configuring SSH Tectia Client </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"connecting_to_a_remote_host_computer.html\">Connecting to a Remote Host Computer</a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Transferring_Files.html\">Transferring Files</a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"tunneling-2.html\">Tunneling Applications</a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"GUI_Reference.html\">GUI Reference</a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"troubleshooting.html\">Troubleshooting </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Command-Line_Tools.html\">Command-Line Tools </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"ssh2.html\">ssh2 </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"scp2.html\">scp2 </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"sftp2.html\">sftp2 </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"ssh-keygen2.html\">ssh-keygen2 </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"ssh-cmpclient.html\">ssh-cmpclient </a>&gt;&gt;<br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Synopsis-5.html\">Synopsis </a><br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Description.html\">Description</a><br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Commands.html\">Commands</a><br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"Options-5.html\">Options</a><br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<font color=\"#303030\">Examples</font><br>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=\"ssh-certview.html\">ssh-certview </a>&gt;&gt;<br>\n</font>\n</td></tr></table>\n\n<h2> <!-- FILENAME:  -->  Examples</h2>\n\n<p> The following <code>ssh-cmpclient</code> examples use <code>pki.ssh.com</code> \n(<a href=\"http://pki.ssh.com/\">http://pki.ssh.com/</a>), a free \ntest PKI interoperability site maintained by SSH Communications \nSecurity. You can try the commands \"as is\" for enrolling certificates to \nyour server. If you are behind a company firewall, you may need to \nprovide a complete SOCKS server URL to <code>ssh-cmpclient</code> with \nthe <code>-S</code> option (for example, <code>-S http://fw.yourdomain.com:1080</code>).\n\n<p> \n\n<h3>  Initial Certificate Enrollment</h3>\n\n<p> This example provides commands for enrolling an initial certificate for \ndigital signature use from the <code>pki.ssh.com</code> interoperability \nsite. It generates a private key into a PKCS #8 plaintext file named \n<code>initial.prv</code>, and stores the enrolled certificate into file \n<code>initial-0.crt</code>. The user is authenticated to the CA with the key \nidentifier (refnum) <code>62154</code> and the key <code>ssh</code>. The subject \nname and alternative IP address are given, as well as key-usage flags. \nThe CA address is <code>pki.ssh.com</code>, the port <code>8080</code>, and the CA name \nto access <code>Test CA 1</code>.\n\n<p> \n<table bgcolor=\"#F0F0F0\" cellspacing=\"0\" cellpadding=\"5\">\n<tr><td>\n<pre>\n$ ssh-cmpclient INITIALIZE \\\n   -P generate://pkcs8@rsa:1024/initial -o initial \\\n   -p 62154:ssh \\\n   -s 'C=FI,O=SSH,CN=Example/initial;IP=1.2.3.4' \\\n   -u digitalsignature \\\n   http://pki.ssh.com:8080/pkix/ \\\n   'C=FI, O=SSH Communications Security Corp, CN=SSH Test CA 1 No Liabilities'\n</td></tr></table>\n\n\n<p> As a response the command presents the issued certificate to the \nuser, and the user accepts it by typing <code>yes</code> at the prompt.\n\n<p> \n<table bgcolor=\"#F0F0F0\" cellspacing=\"0\" cellpadding=\"5\">\n<tr><td>\n<pre>\nCertificate =\n  SubjectName = &lt;C=FI, O=SSH, CN=Example/initial&gt;\n  IssuerName = &lt;C=FI, O=SSH Communications Security Corp, \n    CN=SSH Test CA 1 No Liabilities&gt;\n  SerialNumber= 8017690\n  SignatureAlgorithm = rsa-pkcs1-sha1\n  Validity = ...\n  PublicKeyInfo = ...\n  Extensions =\n      Viewing specific name types = IP = 1.2.3.4\n    KeyUsage = DigitalSignature\n    CRLDistributionPoints = ...\n    AuthorityKeyID =\n      KeyID = 3d:cb:be:20:64:49:16:1d:88:b7:98:67:93:f0:5d:42:81:2e:bd:0c\n    SubjectKeyID =\n      KeyId = 6c:f4:0e:ba:b9:ef:44:37:db:ad:1f:fc:46:e0:25:9f:c8:ce:cb:da\n  Fingerprints =\n    MD5 = b7:6d:5b:4d:e0:94:d1:1f:ec:ca:c2:ed:68:ac:bf:56\n    SHA-1 = 4f:de:73:db:ff:e8:7d:42:c4:7d:e1:79:1f:20:43:71:2f:81:ff:fa\n\nDo you accept the certificate above? yes\n</td></tr></table>\n\n\n<p> \n\n<h3>  Key update</h3>\n\n<p> Before the certificate expires, a new certificate with updated validity \nperiod should be enrolled. <code>ssh-cmpclient</code> supports key update, \nwhere new private key is generated and the key update request is \nauthenticated with the old (still valid) certificate. The old \ncertificate is also used as a template for issuing the new certificate, \nso the identity of the user will not be changed during the key update. \nWith the following command you can update the key pair, which was \nenrolled in the previous example. Presenting the result certificate has \nbeen left out.\n\n<p> \n<table bgcolor=\"#F0F0F0\" cellspacing=\"0\" cellpadding=\"5\">\n<tr><td>\n<pre>\n$ ssh-cmpclient UPDATE \\\n   -k initial.prv -c initial-0.crt -P \\\n   generate://pkcs8@rsa:1024/updatedcert -o updatedcert \\\n   http://pki.ssh.com:8080/pkix/ \\\n   \"C=FI, O=SSH Communications Security Corp, CN=SSH Test CA 1 No Liabilities\"\n</td></tr></table>\n\n\n<p> The new key pair can be found in the files with the <code>updatedcert</code> \nprefix. The policy of the issuing CA needs to also allow automatic key \nupdates if <code>ssh-cmpclient</code> is used in the <code>UPDATE</code> mode. \nThe <code>pki.ssh.com</code> test site, powered by SSH Tectia Certifier, is \nconfigured to allow automatic update of keys based on certificates \nissued earlier.\n\n<p> \n\n</font><font face=\"Arial,Helvetica,sans-serif\" size=\"-2\">\n<p>\n<a href=\"Options-5.html\"><img align=\"center\" border=\"0\" src=\"gfx/prev.gif\" alt=\"Previous\"></a>\n<a href=\"ssh-certview.html\"><img align=\"center\" border=\"0\" src=\"gfx/next.gif\" alt=\"Next\"></a>\n<a href=\"ssh-cmpclient.html\"><img align=\"center\" border=\"0\" src=\"gfx/up.gif\" alt=\"Up\"></a>\n<font face=\"Arial,Helvetica,sans-serif\" size=\"2\">[<a href=\"index.html\">Contents</a>]\n[<a href=\"index-25.html\">Index</a>]\n</font><center>\n<hr width=\"100%\">\n[ <a href=\"Contact_Information.html\">Contact Information</a> | <a href=\"http://www.ssh.com/support/\">Support</a> | <a href=\"http://www.ssh.com/company/contact/feedback.mpl\">Feedback</a> | <a href=\"http://www.ssh.com\">SSH Home Page</a> | <a href=\"http://www.ssh.com/products/\">SSH Products</a> ]\n<p>\nCopyright &copy; 2010 SSH Communications Security Corp.<br>\nThis software is protected by international copyright laws. All rights reserved.<br>\n<a href=\"Copyright_Notice.html\">Copyright Notice</a>\n</font>\n</center>\n</font>\n\n<!-- /main column -->\n          </TD>\n          <TD width=\"20\"><IMG height=\"1\" alt=\"\" src=\"gfx/1x1.gif\" width=\"20\" border=\"0\"></TD>\n\t</TR>\n\t</TBODY>\n\t</TABLE>\n\n</TR>\n</TBODY>\n</TABLE>\n\n<!--<IMG height=\"21\" alt=\"\" src=\"gfx/1x1.gif\" width=\"1\" border=\"0\"> -->\n\n</div>","head":"<HEAD>\n<TITLE>SSH: Examples</TITLE>\n<META http-equiv=\"Content-Type\" content=\"text/html\"; charset=\"iso-8859-1\">\n<LINK href=\"gfx/ssh.css\" type=\"text/css\" rel=\"stylesheet\">\n</HEAD>","url":"/manuals/client-user/44/Examples.html"}}}