This article describes the process of installing or replacing SSH keys for PGP administrators in the PGP Encryption Server console.
Access to the server directly is heavily restricted. The only supported method of access is to install a key into an super-user administrator profile within the PGP Encryption Server console, and then specify that key during an SSH connection.
PGP 11.5 and older
For details on how to create the keys used for SSH, please see the following article:
153592 - Access the PGP Encryption Server by using SSH (Symantec Encryption Management Server)
Once keys are created, you can install them into existing administrators in the console. To do this:
Now that the key is uploaded to the user, you can connect via SSH to the server.
NOTE: If you wish to rotate this key for a user, you can click the Circle/Slash button to the right of the SSHv2 Key and remove the key, and follow the procedure again to upload a new key. Again, be sure to click Save after doing so while viewing the user profile with the changes made.
A common way to connect to the server is by using PuTTY and setting up a profile. Here is an example of a profile you can set up:
You can now double click the entry in the Saved Sessions list, or click load while it's highlighted to start the SSH connection. It will prompt you for a passphrase if your generated SSH key was made with a passphrase (recommended). This will be the passphrase given to the key, not the PGP Encryption Server administrator's passphrase.
Once the passphrase is entered, it will bring you to a command prompt and access is now established.