[j-nsp] ssh host keys on redundant route-engines

Clinton Work clinton at scripty.com
Fri Jul 2 10:56:08 EDT 2004


I have noticed that redundant REs on a Juniper M40e generate their own ssh
host keys. Are there any
problems with copying the ssh host keys from the primary RE to the backup
RE? I'm surprised that
JUNOS doesn't sync the SSH host keys by default. I'm running JunOS 5.7R2.4
right now.


% ls -al /etc/ssh
total 18
drwxr-xr-x  2 root  wheel   512 Jun 18 12:24 .
dr-xr-xr-x  7 root  wheel  1536 Jun 28 23:53 ..
lrwxr-xr-x  1 root  wheel    36 Jun 18 12:24 primes ->
/packages/mnt/jcrypto/etc/ssh/primes
-rw-------  1 root  wheel   668 Dec 19  2003 ssh_host_dsa_key
-rw-r--r--  1 root  wheel   607 Dec 19  2003 ssh_host_dsa_key.pub
-rw-------  1 root  wheel   532 Dec 19  2003 ssh_host_key
-rw-r--r--  1 root  wheel   336 Dec 19  2003 ssh_host_key.pub
-rw-------  1 root  wheel   887 Dec 19  2003 ssh_host_rsa_key
-rw-r--r--  1 root  wheel   227 Dec 19  2003 ssh_host_rsa_key.pub

Thanks.

=========================================================================
Clinton Work                                        clinton at scripty.com
Calgary, Alberta



More information about the juniper-nsp mailing list