RE: Digest of [email protected] issue 73 (739)
"Welsh, Armand" <[email protected]> Fri, 27 Feb 2009 09:05:24 -0800
| Newsgroups | gmane.network.ssh.windows |
|---|---|
| Message-ID | <835E3C9795256845AECB2DF5F53BBD3C188B17@INE000PC.IMSWEST.SSCIMS.com> |
This is a multi-part message in MIME format. ------_=_NextPart_001_01C998FD.949F5EFF Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable And the authorized_keys file that catseverywhere is referring to, is the one in the user's home directory. =20 If the user mmouse is defined on the SSH server with a home directory located at /home/mmouse then the authorized keys file should be located at: /home/mmouse/.ssh/authorized_keys =20 =20 I would also like to comment on something a lot of new users get confused on. As a measure of good security practice: =20 1) the private key should be secured by a password. 2) the key-pair should use DSA (not RSA) 3) the larger the key size, the harder it is to break the key, I recommend at least 1024bits, but I personally use the less supported 2048bits size 4) the private key is required on the client computer, the public key is optional 5) the public key is required on the server (in the user's ~/.ssh/authorized_keys file) 6) never store your private key on the server. If you need for your server to communicate to other SSH servers with DSA/RSA authentication, create a new key pair, and DO NOT EVER store the public key into the authorized_keys of the same computer that retains the private key. This is not because you want to separate the private and public keys, the public keys can always be recreated from the private key. This is because you never want to store the keys to the server in the server. Like a lock, the keys and the locks should never be stored together. The key is used only to unlock the lock, but stored somewhere else. =20 Regards, Armand ________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of catseverywhere Sent: Friday, February 27, 2009 3:53 AM To: [email protected] Subject: Re: Digest of [email protected] issue 73 (739) Each user has their own key, which goes in the authorized_keys file on the server. The same key won't work with different users or from different hardware. [email protected] wrote:=20 Topics (messages 739 through 739): =09 Non Administrator User 739 - Jason Staack <[email protected]> <mailto:[email protected]>=20 =09 =09 =20 ________________________________ Subject:=20 Non Administrator User From:=20 Jason Staack <[email protected]> <mailto:[email protected]>=20 Date:=20 Thu, 26 Feb 2009 10:17:33 -0600 To:=20 [email protected] To:=20 [email protected] Hello, =09 I am able to use a key without being prompted for passphrase/password to log into a linux box with the Administrator user but any other user using the same key (even if they are in the windows administrator group) is asked for the passphrase and password. =09 Thank You =09 -- List Info: http://erdelynet.com/ssh-l/ List Archives: http://erdelynet.com/archive/ssh-l/ To Unsubscribe: Mail mailto:[email protected] If you are having trouble unsubscribing, visit the List Info page for help. =09 =20 --=20 "The more corrupt the state, the more numerous the laws." -- Cornelius Tacitus (55-117 A.D.) -- List Info: http://erdelynet.com/ssh-l/ List Archives: http://erdelynet.com/archive/ssh-l/ To Unsubscribe: Mail mailto:[email protected] If you are having trouble unsubscribing, visit the List Info page for help.=20 ------_=_NextPart_001_01C998FD.949F5EFF Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD><TITLE></TITLE> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.6000.16788" name=3DGENERATOR></HEAD> <BODY text=3D#000000 bgColor=3D#ffffff> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>And the authorized_keys file that = catseverywhere is=20 referring to, is the one in the user's home = directory.</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>If the user mmouse is defined on the SSH server = with a home=20 directory located at /home/mmouse</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>then the authorized keys file should be located = at:</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff = size=3D2>/home/mmouse/.ssh/authorized_keys</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>I would also like to comment on something a lot = of new=20 users get confused on. As a measure of good security=20 practice:</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>1) the private key should be secured by a=20 password.</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>2) the key-pair should use DSA (not=20 RSA)</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>3) the larger the key size, the harder it is to = break the=20 key, I recommend at least 1024bits, but I personally use the less = supported=20 2048bits size</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>4) the private key is required on the = client=20 computer, the public key is optional</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>5) the public key is required on the server (in = the user's=20 ~/.ssh/authorized_keys file)</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>6) never store your private key on = the server. =20 If you need for your server to communicate to other SSH servers with = DSA/RSA=20 authentication, create a new key pair, and DO NOT EVER store the public = key into=20 the authorized_keys of the same computer that retains the private = key. =20 This is not because you want to separate the private and public keys, = the public=20 keys can always be recreated from the private key. This is because = you=20 never want to store the keys to the server in the server. Like a = lock, the=20 keys and the locks should never be stored together. The key is = used only=20 to unlock the lock, but stored somewhere else.</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2></FONT></SPAN> </DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>Regards,</FONT></SPAN></DIV> <DIV dir=3Dltr align=3Dleft><SPAN class=3D896284616-27022009><FONT = face=3DArial=20 color=3D#0000ff size=3D2>Armand</FONT></SPAN></DIV><BR> <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr align=3Dleft> <HR tabIndex=3D-1> <FONT face=3DTahoma size=3D2><B>From:</B> [email protected]=20 [mailto:[email protected]] <B>On Behalf Of = </B>catseverywhere<BR><B>Sent:</B>=20 Friday, February 27, 2009 3:53 AM<BR><B>To:</B>=20 [email protected]<BR><B>Subject:</B> Re: Digest of [email protected] = issue 73=20 (739)<BR></FONT><BR></DIV> <DIV></DIV>Each user has their own key, which goes in the = authorized_keys file=20 on the server. The same key won't work with different users or from=20 different hardware.<BR><BR><BR><A class=3Dmoz-txt-link-abbreviated = href=3D"mailto:[email protected]">[email protected]</A> wrote: = <BLOCKQUOTE cite=3Dmid:[email protected] = type=3D"cite"><PRE wrap=3D"">Topics (messages 739 through 739): Non Administrator User 739 - Jason Staack <A class=3Dmoz-txt-link-rfc2396E = href=3D"mailto:[email protected]"><[email protected]></A> </PRE><BR> <HR width=3D"90%" SIZE=3D4> <BR> <TABLE class=3Dheader-part1 cellSpacing=3D0 cellPadding=3D0 = width=3D"100%" border=3D0> <TBODY> <TR> <TD> <DIV class=3Dheaderdisplayname style=3D"DISPLAY: = inline">Subject: </DIV>Non=20 Administrator User</TD></TR> <TR> <TD> <DIV class=3Dheaderdisplayname style=3D"DISPLAY: inline">From: = </DIV>Jason=20 Staack <A class=3Dmoz-txt-link-rfc2396E=20 = href=3D"mailto:[email protected]"><[email protected]></A></TD></TR> <TR> <TD> <DIV class=3Dheaderdisplayname style=3D"DISPLAY: inline">Date: = </DIV>Thu, 26=20 Feb 2009 10:17:33 -0600</TD></TR> <TR> <TD> <DIV class=3Dheaderdisplayname style=3D"DISPLAY: inline">To: = </DIV><A=20 class=3Dmoz-txt-link-abbreviated=20 = href=3D"mailto:[email protected]">[email protected]</A></TD></TR></TBODY>= </TABLE> <TABLE class=3Dheader-part2 cellSpacing=3D0 cellPadding=3D0 = width=3D"100%" border=3D0> <TBODY> <TR> <TD> <DIV class=3Dheaderdisplayname style=3D"DISPLAY: inline">To: = </DIV><A=20 class=3Dmoz-txt-link-abbreviated=20 = href=3D"mailto:[email protected]">[email protected]</A></TD></TR></TBODY>= </TABLE><BR><PRE wrap=3D"">Hello, I am able to use a key without being prompted for passphrase/password to log into a linux box with the Administrator user but any other user using the same key (even if they are in the windows administrator group) is asked for the passphrase and password. Thank You -- List Info: <A class=3Dmoz-txt-link-freetext = href=3D"http://erdelynet.com/ssh-l/">http://erdelynet.com/ssh-l/</A> List Archives: <A class=3Dmoz-txt-link-freetext = href=3D"http://erdelynet.com/archive/ssh-l/">http://erdelynet.com/archive= /ssh-l/</A> To Unsubscribe: Mail <A class=3Dmoz-txt-link-freetext = href=3D"mailto:[email protected]">mailto:ssh+unsubscribe@erde= lynet.com</A> If you are having trouble unsubscribing, visit the List Info page for = help. </PRE></BLOCKQUOTE><BR><PRE class=3Dmoz-signature cols=3D"72">--=20 "The more corrupt the state, the more numerous the laws." -- Cornelius = Tacitus (55-117 A.D.)</PRE>--=20 List Info: http://erdelynet.com/ssh-l/ List Archives:=20 http://erdelynet.com/archive/ssh-l/ To Unsubscribe: Mail=20 mailto:[email protected] If you are having trouble = unsubscribing,=20 visit the List Info page for help. </BODY></HTML> ------_=_NextPart_001_01C998FD.949F5EFF-- -- List Info: http://erdelynet.com/ssh-l/ List Archives: http://erdelynet.com/archive/ssh-l/ To Unsubscribe: Mail mailto:[email protected] If you are having trouble unsubscribing, visit the List Info page for help.