Once the client application has the router’s public SSH host key, it can then initiate the SSH sequence as if it had created the TCP/IP connection and authenticate the router using its copy of the router’s public host SSH key as part of that sequence. The router authenticates the client user through the mechanisms supported in the JUNOS software (RSA/DSA public string or password authentication).