Authenticate Junos PyEZ Users
Junos PyEZ applications can authenticate users using a password or other standard SSH authentication mechanisms.
Junos PyEZ User Authentication Overview
Junos PyEZ enables you to directly connect to and manage Junos devices using a serial console
connection, telnet, or a NETCONF session over SSH. Junos PyEZ also supports
connecting to a device through a telnet or SSH connection to a console server that
is connected to the device’s CONSOLE port. In addition, Junos PyEZ
can connect to a device through an intermediate device, such as a bastion or jump
host.
The remote devices must be able to authenticate the user using a password or other standard SSH authentication mechanisms, depending on the connection method. When you manage Junos devices through an SSH connection, the most convenient and secure way to access a device is to configure SSH keys. SSH keys enable the remote device to identify trusted users.
You can perform device operations using any user account that has access to the managed Junos
device. You can explicitly define the user when creating a new instance of the
jnpr.junos.device.Device class. If you do not specify a user,
the user defaults to the value of the $USER environment variable.
For SSH connections, Junos PyEZ automatically queries the default SSH configuration file at
~/.ssh/config, if one exists. You can also include
ssh_config in the Device argument list to
specify a different configuration file. Junos PyEZ uses any relevant settings in the
SSH configuration file that are not overridden by the arguments in the
Device argument list, such as the user or the identity
file.
When using SSH to connect to a device, Junos PyEZ first attempts SSH public key-based authentication and then tries password-based authentication. When password-based authentication is used, the supplied password is used as the device password. When SSH keys are in use, the supplied password is the passphrase for unlocking the private key. You do not need to supply a password if you load the key into an SSH key agent or if the SSH private key has an empty passphrase. However, we do not recommend using SSH private keys with empty passphrases.
Obtain credentials in a secure manner appropriate for your environment. As a best practice, prompt for credentials each time you run the script instead of storing them in an unencrypted format.
The following sections discuss the different authentication methods.
Authenticate Junos PyEZ Users Using a Password
To authenticate a Junos PyEZ user using a password:
Authenticate Junos PyEZ Users Using SSH Keys
To use SSH keys in a Junos PyEZ application, you must first generate the keys on the
configuration management server. Then configure the public key on each device to
which the Junos PyEZ client will connect. The devices might include a Junos device,
a console server, or a bastion or jump host. To use the keys, you must include the
appropriate arguments in the Device argument list.
Junos PyEZ can utilize SSH keys that are actively loaded into an SSH key agent, keys that are
generated in either the default location or a user-defined location, and keys that
use or forgo password protection. If the Device arguments do not
specify a password or reference an SSH key file, Junos PyEZ first checks the SSH
keys that are actively loaded in the SSH key agent and then checks for SSH keys in
the default location. When connecting to a console server, the SSH keys must be
password-protected.
The following sections outline the steps for generating the SSH keys, configuring the keys on remote devices, and using the keys to connect to the managed device:
Generate and Configure SSH Keys
To generate SSH keys on the configuration management server and configure the public key on remote devices:
Reference SSH Keys in Junos PyEZ Applications
After you generate the SSH keypair and configure the public key on the remote
device, Junos PyEZ applications can use the key to connect to the device. To use
the key, include the appropriate arguments in the Device
constructor. The Device arguments are determined by:
-
The location of the key
-
Whether the key is actively loaded into an SSH key agent, such as ssh-agent
-
Whether the key is password-protected
-
Whether the user’s SSH configuration file already defines settings for that host
The following sections outline the various scenarios:
- Use an SSH Key Agent with Actively Loaded Keys
- Use SSH Keys Without Password Protection
- Use Password-Protected SSH Keys
Use an SSH Key Agent with Actively Loaded Keys
You can use an SSH key agent, or authentication agent, to securely store
private keys and avoid repeatedly retyping the passphrase for
password-protected keys. A Junos PyEZ client can connect to a device
using SSH keys that are actively loaded into the SSH agent. By default,
if the Device arguments do not specify a password or
reference an SSH key file, Junos PyEZ first checks the SSH keys that are
actively loaded in the SSH key agent and then checks for SSH keys in the
default location. Note that Device can set the SSH key
file explicitly in the argument list or through settings in the SSH
configuration file.
To connect to a device using SSH keys that are actively loaded into the native SSH key agent:
-
To connect directly to a Junos device, you need supply only the required hostname or IP address in the
Deviceargument list.dev = Device(host='router.example.com')
-
To connect to a Junos device through a bastion or jump host, set
hostto the hostname or IP address of the Junos device and include theproxy_commandargument defining the connection through the jump host.dev = Device(host='router.example.com', proxy_command="ssh -W %h:%p -q jumphost.example.com")
The Device constructor also supports the
allow_agent argument to provide finer control over
when to use the SSH key agent. Table 1 outlines the settings.
| allow_agent Values | Behavior |
|---|---|
|
|
The SSH connection uses keys in the SSH agent only if
the |
|
|
The SSH connection uses keys loaded in the SSH agent. |
|
|
The SSH connection does not use keys from the SSH agent. |
For example, suppose you load SSH keys for a host in the SSH key agent.
Additionally, your SSH configuration file contains a host entry that
defines the IdentityFile option with the private key
file for that host. In your Junos PyEZ application, you create an
instance of Device and define only the
host argument. By default, Device
uses the private key file defined by IdentityFile.
Because the Device arguments reference a private key
file, Junos PyEZ does not check the SSH key agent. If the private key
file has a passphrase, the connection fails because no password is
supplied. Thus, to use the SSH agent but retain the
IdentityFile option in the SSH configuration file,
you can set allow_agent=True.
dev = Device(host='router.example.com', allow_agent=True)
Use SSH Keys Without Password Protection
Junos PyEZ enables a client to connect directly to a Junos device using SSH private keys that do not have password protection. However, we do not recommend using SSH private keys with an empty passphrase. Junos PyEZ does not support connecting to a console server using SSH private keys with an empty passphrase.
To connect to a Junos device using SSH keys that are in the default location and do not have password protection:
-
In the
Deviceargument list, you need supply only the required hostname or IP address.dev = Device(host='router.example.com')
Junos PyEZ first checks the SSH keys that are loaded in the active SSH key agent and then checks the SSH keys in the default location.
To connect to a Junos device using SSH keys that are not in the default location and do not have password protection:
-
In the
Deviceargument list, set thessh_private_key_fileargument to the path of the SSH private key.dev = Device(host='router.example.com', ssh_private_key_file='/home/user/.ssh/id_rsa_dc')
Note:If the user’s SSH configuration file already specifies the local SSH private key file path for a given host, you can omit the
ssh_private_key_fileargument in theDeviceargument list. Including thessh_private_key_fileargument overrides any existingIdentityFilevalue defined for a host in the user’s SSH configuration file.
Use Password-Protected SSH Keys
Junos PyEZ clients can use password-protected SSH keys to connect directly to
a Junos device, to a Junos device through a bastion or jump host, or to a
console server connected to the device. The following sections outline how
to explicitly define the Device arguments for
password-protected SSH keys. To instead use password-protected keys loaded
in an active SSH key agent, see Use an SSH Key Agent with Actively Loaded Keys.
Connect Directly to a Junos Device
To connect directly to a Junos device using a password-protected SSH key:
Include code that prompts for the SSH private key password and stores the value in a variable.
from jnpr.junos import Device from getpass import getpass key_password = getpass('Password for SSH private key file: ')
In the
Deviceargument list:Set the
passwdargument to reference the variable containing the SSH key file passphrase.Set the
ssh_private_key_fileargument to the path of the private key, if the key is not in the default location and the SSH configuration file does not already define the private key file path.
from jnpr.junos import Device from getpass import getpass key_password = getpass('Password for SSH private key file: ') dev = Device(host='router.example.com', passwd=key_password, ssh_private_key_file='/home/user/.ssh/id_rsa_dc') dev.open() # ... dev.close()
Connect Through a Jump Host
To connect to a Junos device through a bastion or jump host using password-protected SSH keys for both devices:
Include code that prompts for the SSH private key password for the network device and stores the value in a variable.
from jnpr.junos import Device from getpass import getpass host = "router1.example.com" junos_passwd = getpass("SSH key passphrase for network device: ")
In the
Deviceargument list:Set the
hostargument to the Junos device hostname or IP address.Set the
passwdargument to reference the variable containing the SSH key file passphrase for the Junos device.Set the
ssh_private_key_fileargument to the path of the private key for the Junos device, if the key is not in the default location and the SSH configuration file does not already define the private key file path.Include the
proxy_commandargument and define the connection for the jump host, including the user and identity file, if required.
from jnpr.junos import Device from getpass import getpass host = "router1.example.com" junos_passwd = getpass("SSH key passphrase for network device: ") dev = Device( host=host, passwd=junos_passwd, ssh_private_key_file="/home/user/.ssh/id_rsa_junos", proxy_command="ssh -i /home/user/.ssh/id_rsa_jump -W %h:%p -q user@jumphost.example.com" ) dev.open() print(dev.facts) dev.close()
When you execute the script, the script prompts for the passphrases of the private keys.
Connect Through a Console Server
To connect to a Junos device through a console server that uses a password-protected SSH key file:
-
Include code that prompts for the login credentials for the Junos device and stores each value in a variable.
from jnpr.junos import Device from getpass import getpass junos_username = input('Junos OS username: ') junos_password = getpass('Junos OS password: ')
Include code that prompts for the console server username and private key password and stores each value in a variable.
from jnpr.junos import Device from getpass import getpass junos_username = input('Junos OS username: ') junos_password = getpass('Junos OS password: ') cs_username = input('Console server username: ') cs_password = getpass('Console server key passphrase: ')
In the
Deviceargument list:Set the
hostargument to the console server hostname or IP address.Set the
userandpasswdarguments to the variables containing the Junos OS login credentials.Set the
cs_userargument to the variable containing the console server username.Set the
cs_passwdargument to the variable containing the SSH key file passphrase.Set the
ssh_private_key_fileargument to the path of the private key, if the key is not in the default location and the SSH configuration file does not already define the private key file path.- Set the
portargument to the TCP port that maps to the TTY device on the console server.
from jnpr.junos import Device from getpass import getpass junos_username = input('Junos OS username: ') junos_password = getpass('Junos OS password: ') cs_username = input('Console server username: ') cs_password = getpass('Console server key passphrase: ') with Device(host='cs.example.com', user=junos_username, passwd=junos_password, cs_user=cs_username, cs_passwd=cs_password, ssh_private_key_file='/home/user/.ssh/id_rsa_dc', port=3007) as dev: print (dev.facts) # ...