5 ms·
SSH login without password (authorized_keys)
- Erwin 17y ago1) You should definitely create a passphrase for your private key (you should only be asked to unlock it once due to ssh-agent). Otherwise if someone gets hold of your private key they can login to any machine you have set up an authorized_keys entry on. 2) use ssh-copy-id to install your public key on a remote (and fix up the permissions on ~/.ssh etc. which for me is the #1 case of key based login not working).
- stuff4ben 17y agoand fix up the permissions on ~/.ssh etc. which for me is the #1 case of key based login not working DOH! I just spent the past 15 minutes trying to figure out why it wasn't working until I stumbled upon my .ssh directory having worldly permissions. Was just about to come here and post the same thing. chmod 700 is your friend!
- jerf 17y agossh -vv (with more or fewer vs) is also your friend. IIRC it tells you about the permission error either there or in the sshd log, and you can also find a lot more errors in the -vv output. You should run ssh -vvv on a normal, working connection at least once to get a sense of what normal output is.
- nocivus 17y agoThanks for the cool explanation. I never really dug into ssh that much, just posting a helper to connect without password ;) So basically ssh-agent should be always running and you add your key to it (via ssh-add) and you never enter your password again, but the key still is generated with a passphrase? Correct? Thanks
- nailer 17y agoThis article is somewhat out of date. Modern OpenSSH distro's include 'ssh-copy-id', a single command to transfer, and append one's key to the remote list ofauthenores keys. So: Step 1: ssh-genkey Step 2: ssh-copy-id user@host Done.
- yan 17y agoSome operating systems, including OS X, don't provide that script, but it's easy enough to just download it: http://www.chiark.greenend.org.uk/ucgi/~cjwatson/cvsweb/~checkout~/openssh/contrib/ssh-copy-id?rev=1.8;content-type=text%2Fplain http://www.chiark.greenend.org.uk/ucgi/~cjwatson/cvsweb/~che...
- jsonscripter 17y agossh-copy-id is great, but the connection argument must be quoted, so if you need to use a different port you must use the form: ssh-copy-id 'user@host -p1337' Took me far too long to figure this out :\
- sant0sk1 17y agoActually, step 1 is: ssh-keygen
- nailer 17y agoYou're right. I'm used to verb-noun commands, which are more popular in Unix, and the only option in Powershell.
- nocivus 17y agoThanks for the tip :)
- _pi 17y agoAlso ssh-copy-id will not work if you don't have password authentication enabled. The only way to get ssh keys on top a ssh box without password auth, is to download them with some other method.
- tdavis 17y ago
- ovi256 17y agoI connect to remote machines several times in a typical workday, and this helps to save a bit of time. Furthermore, it allows some non-obvious behaviour, like closing the connection as soon as I did what I wanted. This avoids leaving a ssh session open in which you may erroneusly type a command intended for your local machine. An "svn up" on the wrong machine car ruin your day.
- Tichy 17y agoIsn't that a bit of a security issue? One machine in the network hacked, they are all gone? Then again, hacker's could just install keyloggers if they get hold of one machine. But it would be a bit more effort.
- dtf 17y agoSpeaking of which: According to the MAN documentation for ssh-keygen, host keys must have an empty passphrase, so just leave it blank. We're not making a host key here, are we? Shouldn't a passphrase be employed?
- bcl 17y agoHe also flubbed using ssh-agent. Usually it is run from the login script once. You then do a ssh-add to add your identity to it. Once that is done you don't need to enter your password for that session anymore. You can even allow ssh on other systems to access your agent so you can ssh to another machine, ssh from that machine to a 3rd which will use your agent for the key info. Never leave your key without a passphrase! A good series of articles on ssh bt Brian Hatch can be found here - http://www.hackinglinuxexposed.com/articles/20021211.html http://www.hackinglinuxexposed.com/articles/20021211.html
- surki 17y agoSome more SSH tips 1. Use SSH connection multiplexing If you are connecting to same computer multiple times, this saves up quite a bit of time http://www.revsys.com/writings/quicktips/ssh-faster-connections.html http://www.revsys.com/writings/quicktips/ssh-faster-connecti... 2. Use autossh For a persistent ssh connection (ex. for reverse tunnels) http://www.debianadmin.com/autossh-automatically-restart-ssh-sessions-and-tunnels.html http://www.debianadmin.com/autossh-automatically-restart-ssh...
- antipax 17y agoObscuring his public key tells me this guy doesn't quite understand what the point of public-private key encryption is.
- nocivus 17y agoThanks for all the tips, everyone :D
- deleted 17y ago[deleted]