Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Authenticate Junos PyEZ Users

Junos PyEZ applications can authenticate users using a password or other standard SSH authentication mechanisms.

Junos PyEZ User Authentication Overview

Junos PyEZ enables you to directly connect to and manage Junos devices using a serial console connection, telnet, or a NETCONF session over SSH. Junos PyEZ also supports connecting to a device through a telnet or SSH connection to a console server that is connected to the device’s CONSOLE port. In addition, Junos PyEZ can connect to a device through an intermediate device, such as a bastion or jump host.

The remote devices must be able to authenticate the user using a password or other standard SSH authentication mechanisms, depending on the connection method. When you manage Junos devices through an SSH connection, the most convenient and secure way to access a device is to configure SSH keys. SSH keys enable the remote device to identify trusted users.

You can perform device operations using any user account that has access to the managed Junos device. You can explicitly define the user when creating a new instance of the jnpr.junos.device.Device class. If you do not specify a user, the user defaults to the value of the $USER environment variable.

For SSH connections, Junos PyEZ automatically queries the default SSH configuration file at ~/.ssh/config, if one exists. You can also include ssh_config in the Device argument list to specify a different configuration file. Junos PyEZ uses any relevant settings in the SSH configuration file that are not overridden by the arguments in the Device argument list, such as the user or the identity file.

When using SSH to connect to a device, Junos PyEZ first attempts SSH public key-based authentication and then tries password-based authentication. When password-based authentication is used, the supplied password is used as the device password. When SSH keys are in use, the supplied password is the passphrase for unlocking the private key. You do not need to supply a password if you load the key into an SSH key agent or if the SSH private key has an empty passphrase. However, we do not recommend using SSH private keys with empty passphrases.

Note:

Obtain credentials in a secure manner appropriate for your environment. As a best practice, prompt for credentials each time you run the script instead of storing them in an unencrypted format.

The following sections discuss the different authentication methods.

Authenticate Junos PyEZ Users Using a Password

To authenticate a Junos PyEZ user using a password:

  1. In your favorite editor, create a new file that uses the .py file extension.

    This example uses the filename junos-pyez-pw.py.

  2. Include code that prompts for the hostname or IP address to which to connect, and the username and password for the Junos device.
  3. If the Junos PyEZ client connects to the device through an SSH connection to a console server, prompt for the console server username and password.
  4. If the Junos PyEZ client connects to a port that is different from the default, prompt for the port number.
  5. In the Device constructor argument list:
    • Set the host argument to the variable containing the hostname or IP address of the remote device.

    • Set the user and passwd arguments to the variables containing the Junos OS login credentials.

    • If the Junos PyEZ client connects through an SSH connection to a console server, set the cs_user and cs_passwd arguments to the variables containing the console server login credentials.

    • If the Junos PyEZ client connects to a non-default port, set the port argument to the variable containing the port, where appropriate.

    • Include any additional arguments required for the connection method.

    The following example provides sample code for each of the different connection methods:

    Note:

    All platforms running Junos OS have only the root user configured by default, without any password. When using Junos PyEZ to initially configure a new or zeroized device through a console connection, use user='root', and omit the passwd parameter.

  6. Execute the Junos PyEZ code.

    The program prompts for the hostname, the Junos OS username and password, the console server username and password (when requested), and the port (when requested). The program does not echo the password on the command line.

Authenticate Junos PyEZ Users Using SSH Keys

To use SSH keys in a Junos PyEZ application, you must first generate the keys on the configuration management server. Then configure the public key on each device to which the Junos PyEZ client will connect. The devices might include a Junos device, a console server, or a bastion or jump host. To use the keys, you must include the appropriate arguments in the Device argument list.

Junos PyEZ can utilize SSH keys that are actively loaded into an SSH key agent, keys that are generated in either the default location or a user-defined location, and keys that use or forgo password protection. If the Device arguments do not specify a password or reference an SSH key file, Junos PyEZ first checks the SSH keys that are actively loaded in the SSH key agent and then checks for SSH keys in the default location. When connecting to a console server, the SSH keys must be password-protected.

The following sections outline the steps for generating the SSH keys, configuring the keys on remote devices, and using the keys to connect to the managed device:

Generate and Configure SSH Keys

To generate SSH keys on the configuration management server and configure the public key on remote devices:

  1. On the server, generate the public and private SSH keypair for the required user, and provide any required or desired options. For example:
  2. (Optional) Load the key into the native SSH key agent.
  3. Configure the public key under the appropriate user account on each device to which the Junos PyEZ application will connect, which could include Junos devices, a console server, or a bastion or jumphost.
    • To configure the public key on a Junos device, one method is to load the key from a file.

    • To configure the public key on a server or jumphost, you can use the ssh-copy command.

  4. Verify that the key works by using the key to log in to the device.

Reference SSH Keys in Junos PyEZ Applications

After you generate the SSH keypair and configure the public key on the remote device, Junos PyEZ applications can use the key to connect to the device. To use the key, include the appropriate arguments in the Device constructor. The Device arguments are determined by:

  • The location of the key

  • Whether the key is actively loaded into an SSH key agent, such as ssh-agent

  • Whether the key is password-protected

  • Whether the user’s SSH configuration file already defines settings for that host

The following sections outline the various scenarios:

Use an SSH Key Agent with Actively Loaded Keys

You can use an SSH key agent, or authentication agent, to securely store private keys and avoid repeatedly retyping the passphrase for password-protected keys. A Junos PyEZ client can connect to a device using SSH keys that are actively loaded into the SSH agent. By default, if the Device arguments do not specify a password or reference an SSH key file, Junos PyEZ first checks the SSH keys that are actively loaded in the SSH key agent and then checks for SSH keys in the default location. Note that Device can set the SSH key file explicitly in the argument list or through settings in the SSH configuration file.

To connect to a device using SSH keys that are actively loaded into the native SSH key agent:

  • To connect directly to a Junos device, you need supply only the required hostname or IP address in the Device argument list.

  • To connect to a Junos device through a bastion or jump host, set host to the hostname or IP address of the Junos device and include the proxy_command argument defining the connection through the jump host.

The Device constructor also supports the allow_agent argument to provide finer control over when to use the SSH key agent. Table 1 outlines the settings.

Table 1: Device allow_agent Argument
allow_agent Values Behavior

None (Default)

The SSH connection uses keys in the SSH agent only if the Device arguments do not specify a password or reference a private key file (either explicitly as an argument or through the SSH configuration file).

True

The SSH connection uses keys loaded in the SSH agent.

False

The SSH connection does not use keys from the SSH agent.

For example, suppose you load SSH keys for a host in the SSH key agent. Additionally, your SSH configuration file contains a host entry that defines the IdentityFile option with the private key file for that host. In your Junos PyEZ application, you create an instance of Device and define only the host argument. By default, Device uses the private key file defined by IdentityFile. Because the Device arguments reference a private key file, Junos PyEZ does not check the SSH key agent. If the private key file has a passphrase, the connection fails because no password is supplied. Thus, to use the SSH agent but retain the IdentityFile option in the SSH configuration file, you can set allow_agent=True.

Use SSH Keys Without Password Protection

Junos PyEZ enables a client to connect directly to a Junos device using SSH private keys that do not have password protection. However, we do not recommend using SSH private keys with an empty passphrase. Junos PyEZ does not support connecting to a console server using SSH private keys with an empty passphrase.

To connect to a Junos device using SSH keys that are in the default location and do not have password protection:

  • In the Device argument list, you need supply only the required hostname or IP address.

    Junos PyEZ first checks the SSH keys that are loaded in the active SSH key agent and then checks the SSH keys in the default location.

To connect to a Junos device using SSH keys that are not in the default location and do not have password protection:

  • In the Device argument list, set the ssh_private_key_file argument to the path of the SSH private key.

    Note:

    If the user’s SSH configuration file already specifies the local SSH private key file path for a given host, you can omit the ssh_private_key_file argument in the Device argument list. Including the ssh_private_key_file argument overrides any existing IdentityFile value defined for a host in the user’s SSH configuration file.

Use Password-Protected SSH Keys

Junos PyEZ clients can use password-protected SSH keys to connect directly to a Junos device, to a Junos device through a bastion or jump host, or to a console server connected to the device. The following sections outline how to explicitly define the Device arguments for password-protected SSH keys. To instead use password-protected keys loaded in an active SSH key agent, see Use an SSH Key Agent with Actively Loaded Keys.

Connect Directly to a Junos Device

To connect directly to a Junos device using a password-protected SSH key:

  1. Include code that prompts for the SSH private key password and stores the value in a variable.

  2. In the Device argument list:

    • Set the passwd argument to reference the variable containing the SSH key file passphrase.

    • Set the ssh_private_key_file argument to the path of the private key, if the key is not in the default location and the SSH configuration file does not already define the private key file path.

Connect Through a Jump Host

To connect to a Junos device through a bastion or jump host using password-protected SSH keys for both devices:

  1. Include code that prompts for the SSH private key password for the network device and stores the value in a variable.

  2. In the Device argument list:

    • Set the host argument to the Junos device hostname or IP address.

    • Set the passwd argument to reference the variable containing the SSH key file passphrase for the Junos device.

    • Set the ssh_private_key_file argument to the path of the private key for the Junos device, if the key is not in the default location and the SSH configuration file does not already define the private key file path.

    • Include the proxy_command argument and define the connection for the jump host, including the user and identity file, if required.

When you execute the script, the script prompts for the passphrases of the private keys.

Connect Through a Console Server

To connect to a Junos device through a console server that uses a password-protected SSH key file:

  1. Include code that prompts for the login credentials for the Junos device and stores each value in a variable.

  2. Include code that prompts for the console server username and private key password and stores each value in a variable.

  3. In the Device argument list:

    • Set the host argument to the console server hostname or IP address.

    • Set the user and passwd arguments to the variables containing the Junos OS login credentials.

    • Set the cs_user argument to the variable containing the console server username.

    • Set the cs_passwd argument to the variable containing the SSH key file passphrase.

    • Set the ssh_private_key_file argument to the path of the private key, if the key is not in the default location and the SSH configuration file does not already define the private key file path.

    • Set the port argument to the TCP port that maps to the TTY device on the console server.