SSH

Tectia® ConnectSecure 6.3

Administrator Manual

SSH Communications Security Corporation

This software and documentation are protected by international copyright laws and treaties. All rights reserved.

ssh® and Tectia® are registered trademarks of SSH Communications Security Corporation in the United States and in certain other jurisdictions.

SSH and Tectia logos and names of products and services are trademarks of SSH Communications Security Corporation. Logos and names of products may be registered in certain jurisdictions.

All other names and marks are property of their respective owners.

No part of this publication may be reproduced, published, stored in an electronic database, or transmitted, in any form or by any means, electronic, mechanical, recording, or otherwise, for any purpose, without the prior written permission of SSH Communications Security Corporation.

THERE IS NO WARRANTY OF ANY KIND FOR THE ACCURACY, RELIABILITY OR USEFULNESS OF THIS INFORMATION EXCEPT AS REQUIRED BY APPLICABLE LAW OR EXPRESSLY AGREED IN WRITING.

For Open Source Software acknowledgements, see appendix Open Source Software License Acknowledgements in the Administrator Manual.

30 March 2016


Table of Contents

1. About This Document
Product information
Documentation Conventions
Operating System Names
Directory Paths
Customer Support
Component Terminology
2. Installing Tectia ConnectSecure
Preparing for Installation
System Requirements
Hardware and Disk Space Requirements
Licensing
Installation Packages
Upgrading Previously Installed Tectia ConnectSecure Software
Downloading Tectia Releases
Installing the Tectia ConnectSecure Software
Installing on AIX
Installing on HP-UX
Installing on Linux
Installing on Solaris
Installing on Windows
Removing the Tectia ConnectSecure Software
Removing from AIX
Removing from HP-UX
Removing from Linux
Removing from Solaris
Removing from Windows
Files Related to Tectia ConnectSecure
File Locations on Unix
File Locations on Windows
Registry Keys on Windows
Symlinks between ssh/scp/sftp and sshg3/scpg3/sftpg3 (on Unix)
3. Getting Started with Tectia ConnectSecure
Product Components
First Login to a Remote Host
Logging in with Tectia SSH Terminal GUI (on Windows)
Logging in with Command-Line sshg3
Using Public-Key Authentication
Configuring Tectia ConnectSecure
Connection Broker Configuration
Connection Broker Configuration Files
Command-Line Tools
Creating Connection Profiles
Defining Connection Profile Settings
Enabling FIPS 140-2 Mode
Enabling FIPS Mode Using Configuration GUI
Enabling FIPS Mode Using Configuration File
FIPS-Certified Cryptographic Library
4. Authentication
Supported User Authentication Methods
Compatibility with OpenSSH Keys
Server Authentication with Public Keys
Host Key Storage Formats
Using the System-Wide Host Key Storage
Resolving Hashed Host Keys
Using the OpenSSH known_hosts File
Server Authentication with Certificates
Managing CA Certificates with the Configuration File (Unix)
Managing CA Certificates with the GUI
User Authentication with Passwords
Defining Password Authentication with the Configuration File (Unix)
Using Stored Passwords in Connection Profiles
Managing Authentication Methods with the GUI
User Authentication with Public Keys
Creating Keys with ssh-keygen-g3
Uploading Public Keys Manually
Creating Keys with the Public-Key Authentication Wizard
Using Keys Generated with OpenSSH
Special Considerations with Windows Servers
User Authentication with Certificates
Using the Configuration File (Unix)
Configuring User Authentication with Certificates on Windows
Importing PKCS Certificates with Tectia Connections Configuration GUI
Host-Based User Authentication (Unix)
User Authentication with Keyboard-Interactive
Defining Keyboard-Interactive Method with the Configuration File (Unix)
Defining Keyboard-Interactive Method with the GUI
User Authentication with GSSAPI
Defining GSSAPI Method with the Configuration File (Unix)
Defining GSSAPI Method with the GUI
5. Secure File Transfers
Secure File Transfer with scpg3 and sftpg3 Commands
Using scpg3
Using sftpg3
Enhanced File Transfer Functions
Secure File Transfer GUI (Windows)
Defining Secure File Transfer GUI Settings
Downloading Files with Tectia Secure File Transfer GUI
Uploading Files with Tectia Secure File Transfer GUI
Transfer and Queue Tabs
Defining File Properties
Differences from Windows Explorer
Controlling File Transfer
Site Command
FTP-SFTP Conversion
Principle of FTP-SFTP Conversion
Requirements for FTP-SFTP Conversion
Enabling FTP-SFTP Conversion (Windows)
Enabling FTP-SFTP Conversion (Unix)
Transparent FTP Tunneling
Principle of Transparent FTP Tunneling
Requirements for Transparent FTP Tunneling
Enabling Transparent FTP Tunneling (Windows)
Enabling Transparent FTP Tunneling (Unix)
Enabling Direct MVS Data Set Access (z/OS)
File Transfer APIs
6. Secure Shell Tunneling
Local Tunnels
Transparent TCP Tunneling
Non-Transparent TCP Tunneling
Non-Transparent FTP Tunneling
SOCKS Tunneling
Remote Tunnels
X11 Forwarding
Agent Forwarding
7. Troubleshooting Tectia ConnectSecure
Gathering Basic Troubleshooting Information
Collecting System Information for Troubleshooting
Setting Connection Broker to Debug Mode
Answers to Common Problems
A. Connection Broker Configuration Tools
Tectia Connections Configuration GUI
Opening the GUI
Defining General Settings
Defining Connection Profiles
Defining User Authentication
Defining Server Authentication
Defining Transparent Tunnels
Defining Automatic Tunnels
Configuration File for the Connection Broker
Backup of Configuration Files
Broker Configuration File Syntax
Tectia Shortcut Menu (Windows and Linux)
Tectia Connections Status GUI
B. Configuring Tectia SSH Terminal GUI and Tectia Secure File Transfer GUI (Windows)
Defining Global Settings
Defining the Appearance
Selecting the Font and Terminal Window Size
Selecting Colors
Defining Messages
Defining File Transfer Settings
Defining Advanced File Transfer Options
Defining File Transfer Mode
Defining Local Favorites
Defining Security Settings
Printing
Using Command-Line Options
Customizing the User Interface
Saving Settings
Loading Settings
Customize Dialog
Customizing Toolbars
Logging a Session
C. Command-Line Tools and Man Pages
ssh-broker-g3 - Tectia Connection Broker - Generation 3
ssh-broker-ctl - Tectia Connection Broker control utility
ssh-troubleshoot - tool for collecting system information
sshg3 - Secure Shell terminal client - Generation 3
scpg3 - Secure Shell file copy client - Generation 3
sftpg3 - Secure Shell file transfer client - Generation 3
ssh-capture (on Unix) - Captures TCP connections for tunneling or FTP-SFTP conversion
ssh-translation-table - Secure Shell Translation Table
ssh-keygen-g3 - authentication key pair generator
ssh-keyfetch - Host key tool for the Secure Shell client
ssh-cmpclient-g3 - CMP enrollment client
ssh-scepclient-g3 - SCEP enrollment client
ssh-certview-g3 - certificate viewer
ssh-ekview-g3 - external key viewer
D. Egrep Syntax
Egrep Patterns
Escaped Tokens for Regex Syntax Egrep
Character Sets For Egrep
E. Audit Messages
F. Removing OpenSSL from Tectia ConnectSecure
Background Information
OpenSSL in Tectia
Should I Remove the OpenSSL Library?
What Happens If I Remove the OpenSSL Library?
Removing the OpenSSL Cryptographic Library
Unix
Windows
G. Open Source Software License Acknowledgements
Index