12 ms·
SSH Kung Fu
- patio11 12y agoA trick I learned recently: create .ssh/config File format: as many of the following blocks as you like Host $ALIAS <-- whatever you want here Hostname www.example.com User someuser Port 1234 You can now ssh to that server as that user by doing "ssh $ALIAS" on the command line, without needing to specify the port or user with the usual command line arguments, or necessarily spell out the entire host name.
- deanclatworthy 12y agoI've been doing this for a while now, but my file is now huge and it's cumbersome to edit. Is there no utility to mange that file?
- pmh 12y agoI don't know of any, but one thing you can do is split up your config into multiple files and then use `cat` to combine them after making a change. There's also https://github.com/markhellewell/sshconfigfs https://github.com/markhellewell/sshconfigfs
- datr 12y agoI've worked around this by creating a ~/.ssh/config.d directory and splitting my configuration out into multiple files (normally by project). I then use dotdee[1] to watch that directory and automatically rebuild ~/.ssh/config anytime there is a change. [1] https://launchpad.net/dotdee https://launchpad.net/dotdee
- batuhanicoz 12y agoI think storm[0] is what you are looking for. [0] https://github.com/emre/storm https://github.com/emre/storm
- SnacksOnAPlane 12y agoHere's what I put in my .bashrc: alias compile-ssh-config='echo -n > ~/.ssh/config && cat ~/.ssh/*.config > ~/.ssh/config' alias ssh='compile-ssh-config && ssh' Compiles all your ~/.ssh/*.config files into a single ssh config file. It's simple and stupid and seems to do the trick.
- lexandstuff 12y agoAside from the ones already mentioned, there's a library called dot-ssh-config[1] that is useful for generating SSH configs. [1] https://github.com/aelse/dot-ssh-config https://github.com/aelse/dot-ssh-config
- hf 12y agoWhat is more, you can specify an abstraction for the tedious double-ssh where you first connect to some internet-facing host in order to gain access to an internal machine: Host $ALIAS User $USER HostName $INTERNAL ProxyCommand ssh $USER2@$PUBLIC -W %h:%p Now laptop> ssh jim@public.example.com public> ssh dev@myworkstation becomes laptop> ssh work (I just realized that this slightly confused article seems to accomplish the same by using a convoluted setup of port-forwardings and netcat.)
- Erwin 12y agoThe ssh -W option -- which replaces netcat -- is relatively new. E.g. Redhat 5.x did not have it, nor did Ubuntu 10.04 LTS. Until OpenSSH 5.4 netcat was the way to do this sort of proxying.
- stock_toaster 12y agoI ran into an issue[1] with the combination of -W and control persist -- using openssh versions < 6.0. netcat worked fine. [1]: https://news.ycombinator.com/item?id=4678117
- sampo 12y agoAnd if your router keeps dropping idle connections, add something like: ServerAliveInterval 240 ServerAliveCountMax 5
- voltagex_ 12y agoCan help on mobile (3G/4G) connections too.
- sampo 12y ago> (I just realized that this slightly confused article seems to accomplish the same by using a convoluted setup of port-forwardings and netcat.) Yeah, the article sets separately first Host bar ... and then Host behind.bar ... But it can also be done by just one step: host behindbar User <user-behindbar> Hostname behindbar.domain ProxyCommand ssh <user-bar>@bar.domain nc %h %p 2> /dev/null
- yen223 12y agoThis is excellent advice. The best part is that you can use the same $ALIAS for tools built on SSH, including scp and rsync, like this: scp $ALIAS:/var/log/mylogs/logfile ~/backups/logs/
- mverwijs 12y agoAnd.... Ansible uses those aliases too, making it trivial to maintain *NIX server that are behind firewalls and/or vpns.
- sampo 12y agoThe aliases also work when mounting filesystems over the network in the File Browser. Nautilus / Connect to Server / Server Address: work/home/user (here 'work' is the alias for the work computer)
- nnnnni 12y agoWell, that sure beats my .bashrc that's full of alias "servername"="ssh user@servername -p portnum"...
- mpapi 12y agoA favorite .ssh/config feature of mine is pattern matching on hostnames with "?" and "*". So you can say something like: Host bos-?? HostName %h.mydomain.com IdentityFile ~/.ssh/my-boston-key Host nyc-?? HostName %h.mydomain2.com IdentityFile ~/.ssh/my-nyc-key and log in with e.g. "ssh bos-14".
- gatehouse 12y agoYeah, I use a similar thing for ec2: Host *.amazonaws.com User ec2-user IdentityFile ... And then it is just ssh ec2-X-X-X-X.compute-1.amazonaws.com
- voltagex_ 12y agoThis seems to be relatively new. It doesn't work on a couple of boxes I tried. Thanks though, I didn't know about the ?? syntax.
- mpapi 12y agoI found references to it going back to 2008, and the git repo that has my dotfiles says I've been using it (in Linux) for 3 or so years. Maybe it depends on the OS/distro. The patterns are similar to shell globs: * matches zero or more characters, ? matches exactly one.
- opendais 12y agoI'm confused how this is better than just using an alias/profile? Maybe it is just me, but I prefer to dump all my custom commands and aliases into .zshrc so they are easy to backup/track/find.
- mturmon 12y agoYou have been down voted, but the question is reasonable. One reason is so that invocations of ssh outside of the context of user invocation of ssh at the command line will also have these customizations included. This is especially important for ssh, which has emerged as a main security interoperability tool for Unix systems. For example, if you use rsync, the tunneling and host alias conventions you set up in .ssh/ will carry over transparently to the ssh tunnel used by rsync. Another example would be invocations of ssh in scripts (sh/bash scripts, even) that will not or might not read your .zshrc.
- opendais 12y agoYa, I think the underlying issue is I do things very differently than people on HN. The idea of creating dependencies on a configuration profile inside a bash script is the exact opposite of what I would do. I also could not rsync things to my local machine [bandwidth constraints] and would be rsyncing between remote machines, which being a shared environment, I would rely on explicit invocations instead of creating configurations/aliases. Thank you for telling me how/why other people make different choices. I always do seem to have the blinders of my process is the only process I consider when commenting on HN. :)
- wilmoore 12y agoTo add to what @mturmon said; you'll want to keep in mind that even GUI tools (i.e. consider your favorite database tool that supports SSH connection) that support SSH connection will pick up this configuration so you don't have to manually plug in all of the pieces for each session. Just specify the alias host name as configured in ~/.ssh/config and the user, identify file, and anything else you put there will be used as set.
- 12y ago
- m1crofarmer 12y agoWhat's more, you can specify as many Host aliases (on one line) as you want (with wildcards): Host 192.168.* *.foo.*.com *.bar.net
- hibbelig 12y agoSadly, this doesn't work always. Some apps which implement their own ssh don't support ~/.ssh/config. For example, the OSX Subversion GUI client Cornerstone doesn't support this.
- Piskvorrr 12y agoAnother useful (albeit ugly) hack is accessing a NATed host which doesn't even have a port forwarded, via an intermediate SSH host outside the target network: http://superuser.com/questions/277218/ssh-access-to-office-host-behind-nat-router/277220#277220 http://superuser.com/questions/277218/ssh-access-to-office-h... (disclaimer: tooting my own horn here, but it is a mighty useful trick)
- peteretep 12y agoFrom the article: > No more password prompts Is that - you ask - because he's using ssh-agent? No, it's because he doesn't tell you you should be using a password-protected key. Some kung fu.
- WestCoastJustin 12y agoThere are many cases where you do not want, or cannot have a password protected ssh trust. For example, say you have a central nagios host monitoring a network, that nagios host needs to connect to remote machines to run interesting monitoring scripts (disk % full, raid controller query, mpio checks, etc), in these cases you do not want to have a password blocking the ssh trust. You will also find this type of thing happening in many continuous deployment workflows as bits are moving from one machine to the other. This is very common practice.
- peteretep 12y agoThat does indeed sound like such a case. However, none of these cases appear to be what the article is addressing; it's just telling you to use non-password-protected keys, with absolutely no discussion of it.
- egil 12y agoIn that case, you would lock down the key so it could only be used to execute the strict subset of commands to do its job. It is very common practice, but is not mentioned at all in the blog post.
- viraptor 12y agoThese sound like exactly the cases where you shouldn't use ssh. Use nrpe instead, or run the check on the target machine from cron and make it report back. There's no reason to use ssh for it and at scale ssh adds considerable load to the monitoring host when starting the connection. For continuous deployment you can't easily work around using ssh, but at least the access can be limited to specific commands only.
- deleted 12y ago
- magnetikonline 12y agoSome good tips here - I like Controlmaster/Controlpath. Note that on the tip of ~/.ssh/known_hosts providing ssh auto completion, adding SSH server config to ~/.ssh/config will also enable auto completion.
- shabble 12y agoIt's great for tab-completion of remote paths for scp & friends. It does have a few quirks though. One that I've noticed is (IIRC) that closing a shared session isn't sufficient to pick up new groups membership when you reconnect. You actually need to kill the master connection as well[0]. The syntax for shutting down a master connection is a bit clunky as well: ssh -O stop -S ~/.ssh/mux/socketname hostname I've been meaning to make a little script or 2 that finds the current mux sockets and tests them with -O check and give you a list of simple IDs you can 'ssh-mux-kill $id' or something. In fact, it'd probably be a nice use for percol[1] [0] There might be other ways of refreshing group memberships, but I don't know of any. [1] https://github.com/mooz/percol https://github.com/mooz/percol
- terhechte 12y ago> Sharing Connections I've tried this before, and what effectively always happened (to me) is that as soon as I started copying a file, I couldn't continue working in Vim anymore until the file was done transmitting because the copying would eat all the bandwidth. There may be a flag or setting around this, but I've never found it. When I open two connections, it is usually fine.
- XorNot 12y agoI've found it just tends to have the primary connection die, and never tries to reconnect. ServerKeepAlives or what have you don't seem to help either - the link goes dead, and I won't be able to connect any other sessions because SSH will just keep on routing them into the control master.
- Piskvorrr 12y agoUsing autossh for establishing the master connection helps immensely here - if it dies, it will automagically reconnect.
- michaelmior 12y agoI have had this problem, although fairly rarely. I have the following in my ~/.ssh/config: ControlPath /tmp/ssh_mux_%h_%p_%r This sets the path of the control file used to share the connection. If it ever hangs, I can just delete the file. But in practice I found this doesn't happen often and I appreciate the speed boost I get from connection sharing.
- shabble 12y agoone minor annoyance is that there's a max limit to the ControlPath string (seemingly due to there being a max path length for Unix Sockets) which I've occasionally hit when connecting to hosts with very long hostnames (AWS default hostnames can sometimes hit it, IIRC). Also note that the docs recommend against using publicly accessible dirs such as /tmp/ for storing your mux sockets. I'm not sure of the exact threat (maybe just info leakage about what hosts you're connected to, since the socket permissions themselves are strict), but I use ~/.ssh/mux/ for mine.
- Morgawr 12y agoI just learned about remote file editing with vim and scp thanks to this article, it's the only thing I didn't know about and... wow, it's amazing. This will make my life much easier every time I have to remotely edit some config files on my servers. As for the rest of the article, really nice stuff. Nice tricks for ssh newbies. I wish he also talked about setting up a nonce system with ssh or move sshd to a non-default port to prevent attackers spamming port 22, or even remove password authentication altogether.
- Piskvorrr 12y agoMoving ssh port is, IMNSHO, a stopgap measure; you should have exhausted all the other options (e.g. no passwords, no root login, denyhosts/fail2ban etc.) before this even crosses your mind. In other words, the inconvenience this brings is not adequate to the infinitesimal increase in security.
- smtddr 12y agoFor me I just don't like seeing /var/log/auth.log being filled with 100s of lines of: Failed password for root2 from 82.192.86.44 port 44990 ssh2 Failed password for admin from 82.192.86.44 port 44990 ssh2 Failed password for sysdb from 82.192.86.44 port 44990 ssh2 Failed password for scott from 82.192.86.44 port 44990 ssh2 (Yes, that IP has scanned my machine before)
- Piskvorrr 12y agoAnd that's exactly what denyhosts is for. You'll see this line a few initial times, then the banhammer springs into action. (It's fully configurable - the number of failed attempts, the length of the autoban, etc.)
- throwaway2048 12y agountil one of the millions of other compromised IPs begins hammering your machine minutes later..
- edwintorok 12y agoThe article mentions ECDSA, but doesn't mention Ed25519, which is supported since OpenSSH 6.5: https://lwn.net/Articles/583485/ https://lwn.net/Articles/583485/ As a bonus Ed25519 keys unconditionally use bcrypt for protecting the private key
- hf 12y agoThe situation with beginner-friendly SSH tutorials is, in a much lesser degree perhaps, comparable to the crypto texts: Good will alone does more harm than good. This treatment ssh does not mention ssh-agent and, more importantly perhaps, implies that there is a certain virtue in having private keys unprotected by sturdy passphrases lying around. There is not; most emphatically not.
- voltagex_ 12y agoHypothetically, if one was reading this article and had a large number of unprotected private keys around, one could change the password on these keys by issuing ssh-keygen -f id_rsa -p
- hf 12y agoA few commenters do not seem to be aware that it is perfectly possible to use passphrase-protected keys for automated tasks (cronjobs and the like). The excellent (though unfortunately named) keychain[0] utility provides a ready and powerful abstraction for both ssh-agent and gpg-agent. [0] https://github.com/funtoo/keychain https://github.com/funtoo/keychain
- dmourati 12y agoHuge fan. The old IBM SSH developerworks series is my favorite primer for folks new to SSH: http://www.ibm.com/developerworks/library/l-keyc.html http://www.ibm.com/developerworks/library/l-keyc.html http://www.ibm.com/developerworks/library/l-keyc2/ http://www.ibm.com/developerworks/library/l-keyc2/ http://www.ibm.com/developerworks/library/l-keyc3/ http://www.ibm.com/developerworks/library/l-keyc3/
- icebraining 12y agoThis is why reading the man pages is useful; you'd get all this and more, including: - X11 Forwarding - Reverse forwarding (bind listening sockets on the remote machine, redirecting to a local service) - SSH-Based VPNs
- hf 12y agoWhile we are busy dispensing wisdom: Do use PermitRootLogin without-password instead of 'yes' in /etc/ssh/sshd_config if you absolutely must have ssh root access.
- Piskvorrr 12y agoIf you must allow SSH root access, in 2014, you are doing something horribly wrong, and this will come back to bite you.
- Sae5waip 12y agoDid you ever stop and think about this or are you just repeating something you read on "Hacker""news"? Getting by /without/ direct SSH root access is often impractical (think about scp), and without-password is a secure way to have it. Also, the more people know about "without-password", the less people will set PermitRootLogin to "yes".
- jfindley 12y agoRequiring admins to ssh to a different, unique-to-them, user, and use sudo from there for any operations requiring root is much better. It's far easier to audit what's been done to the server, which is important not just for compliance but also for figuring out why something's broken suddenly. It also means that you get to have your own shell history, your own shell settings, your own vim settings, etc, etc. In general, having proper deployment, log collection and config management tools in place tends to mean you rarely need to scp files around at all - and the cases when you do, you can work around this by scping them to some other dir, and moving them locally with a sudo command.
- shabble 12y ago...which is fine up until someone forgets to use visudo and buggers up the sudoers file so nobody can get back in to fix it. A user login followed by su to root is a valid alternative, but I wouldn't have a problem with allowing key-only root access via sshd either. You'd want the root key/password to be very tightly controlled for the reasons you mention, but having it set is (IMO) a worthwhile backup plan for when things go wrong.
- luxpir 12y agoOne problem I have with SSH is DPI. Deep Packet Inspection seems to be behind the SSH block in place at a local library I work at. SSH out in any form just isn't possible there, even via a browser-based console (such as that used by Digital Ocean, for example). There doesn't seem to be a suitable solution to get around it offered anywhere. My own fix was to use 3G to do the SSH work via a tethered phone and to use the wifi adapter to run the bulk of any other web traffic. It'd be great to have a workaround for DPI, though, if anyone has any experience there.
- icebraining 12y agoIf the browser-based console is also blocked, there's something fishy going around, since that doesn't use SSH. In any case, you can try proxying SSH over SSL using stunnel: http://askubuntu.com/questions/423727/ssh-tunneling-over-ssl http://askubuntu.com/questions/423727/ssh-tunneling-over-ssl Or you could try setting up OpenVPN, it's easy enough.
- luxpir 12y agoI didn't want to spend too much time poking around, but it seemed odd to me too (wrt the browser-console). Cheers for the stunnel/OpenVPN thoughts, they ought to get through. It would be great if SSH could itself emulate SSL, in the modern context of increased security requirements and censorship.
- phaemon 12y agoSSH over SSL seems to be what you need. Try: http://blog.chmd.fr/ssh-over-ssl-a-quick-and-minimal-config.html http://blog.chmd.fr/ssh-over-ssl-a-quick-and-minimal-config....
- luxpir 12y agoDoes seem to do the trick, and I have half of that already set up - just need to work out the config for Nginx. It's a smart workaround indeed. Thanks for that.
- stock_toaster 12y ago
- grn 12y agoI can recommend Mastering SSH - it's a nice, short read. http://www.amazon.com/SSH-Mastery-OpenSSH-PuTTY-Tunnels-ebook/dp/B006ZO9ULK/ http://www.amazon.com/SSH-Mastery-OpenSSH-PuTTY-Tunnels-eboo...
- Nick_C 12y agoI can't. I bought with some high expectations, unfortunately I knew almost everything in it from a couple of years of using ssh to my several VPSs. I was quite disappointed at the level of detail it had -- StackExchange level, I thought.
- grn 12y agoYou're right that it doesn't go into detail but it's short and provides high-level overview of the most important features. It's much easier to learn the basic of something from a book and then find the details in the manual than working with the manual only. But if someone expects to gain deep, expert level knowledge of how OpenSSH works then he'll be disappointed. What expert-level books can you recomment?
- Nick_C 12y agoUnfortunately, I can't recommend anything, but I'm not a wide reader on the topic so my knowledge is limited. Perhaps I was a bit hard on that book, my expectations were that it would be a deep, expert type of book. If that's not what you are looking for, it is perfectly fine. Actually, now that I think about it, the epub version is good to keep on your mobile phone as a handy, easily-accessible reference for use in the coffee shop, so I guess it does get a credit from me.
- bryanlarsen 12y agoAnother recommendation: start an SSH server on port 443 on a server somewhere. Then if you're stuck somewhere on an untrusted network, one that blocks most outgoing ports or one that throttles non-HTTP ports, you can use SSH for tunneling and/or setting up a quick SOCKS proxy to get yourself encrypted, unblocked, full speed internet access.
- vinceguidry 12y agoIs sshfs a serious replacement for nfs? I've got a Buffalo Nas at home that I use Samba for, but Samba is too slow to watch hi-def videos over. NFS seems to be a pain in the neck to get working on that particular device, and I hate using it on a laptop. I guess I should probably just try it, but I can't see SSHFS as being any faster than Samba.
- stephen_g 12y agoIt'll probably be less performant than NFS, but is a really great and simple way for mounting remote volumes securely across the internet without having to worry about VPNs or any extra authentication or anything.
- turrini 12y agoTry: # sshfs -o direct_io,nonempty,allow_other,cache=no,compression=no,workaround=rename,workaround=nodelaysrv user@remote:/place/ /mnt/somewhere For even more performance: * On server, start socat: # socat TCP4-LISTEN:7001 EXEC:/usr/lib/sftp-server * On client, do: # sshfs -o directport=7001,direct_io,nonempty,allow_other,cache=no,compression=no,workaround=rename,workaround=nodelaysrv user@remote:/place/ /mnt/somewhere
- voltagex_ 12y agoWhoa, what do all those options do?
- ak217 12y agoBest trick I learned in the past few years is SSH control sequences. Disconnected from your host but not timed out yet? Press Enter, ~, . and the client will quit.
- themckman 12y agoOhh my, the day I learned this was one of the happiest in all my life. You can also configure this in your .ssh/config with EscapeChar, if you find yourself SSHing into other machines from a machine you're already SSHed into.
- eieio 12y agoYou can also use send a double tilde ( Enter, ~, ~) to pass a tilde to your inner ssh session. So killing a session within a session is Enter, ~, ~, .
- mrlebowski 12y agoI have a setup similar to this: laptop - user (userid: me) F - firewall (userid: me) A - machine 1 in colo (userid: colo) B - machine 2 in colo (userid: colo, machine I want to access) C - machine 2 in colo (userid: colo) . . 100s of machines. Trust (ssh password less login) is setup between me@laptop and me@F, and me@laptop and colo@A, and between all colo machine (A,B,C..). So colo@A can ssh colo@B w/o password. I am able to log into colo@A via F w/o password as I copied the ssh key there manually. (path me@laptop -> colo@F -> colo@A) QUESTION: Is it possible to ssh to other machines (B,C..) via A while assuming full identity of colo@A? (Path would be me@laptop -> colo@F -> colo@A -> colo@B/C/..) With my current config when I try to ssh to B it knows request is originating from 'laptop' and still asks me for password.
- Tyr42 12y agoI think this guy answered it https://news.ycombinator.com/item?id=7658742 https://news.ycombinator.com/item?id=7658742 ProxyCommand ssh ...
- ambrop7 12y agoAbout the "Lightweight Proxy" (ssh -D), if you want it to be transparent to the application (not require SOCKS support), you can use my tun2socks[1] program. This is useful if you can't or don't want to set up an SSH tunnel (which requires root permissions on the server). The linked page actually explains exactly this use case. It even works on Windows ;) [1] https://code.google.com/p/badvpn/wiki/tun2socks https://code.google.com/p/badvpn/wiki/tun2socks
- marianov 12y agoOr use tsocks. Proxies everything that uses tcp through a socks proxy (ssh -D) http://manpages.ubuntu.com/manpages/hardy/man1/tsocks.1.html http://manpages.ubuntu.com/manpages/hardy/man1/tsocks.1.html
- ambrop7 12y agoNot system-wide though, and possibly incompletely and with bugs. The entire socket API is far from being simple to wrap like this, especially when you consider that it includes all the various IO functions (read/write, send/recv, recvmsg/sendmsg), nonblocking operation with select, poll, epoll, the p* versions of these with special behavior with respect to signals, the integration of these polling functions with non-wrapped fds, various socket options, splice functions, thread safety, shutdown semantics... It shouldn't be hard to find a program which runs fine with tun2socks but breaks completely or subtly with tsocks.
- radoslawc 12y agofor me best trick with ssh so far is to use ssh as proxy command: ssh -o ProxyCommand="ssh -W %h:%p user@ssh_jump_host.somedomain.net -p some_non_22_port" user@some_host_inside.lan -D 1234 above creates dynamic tunel (for use as socks proxy) through jumphost to reach http hosts available only to some_host_inside.lan machine
- MichaelMoser123 12y agoVery interesting article; I have a shell script that helps with setting up trusted keys: trusted keys help if you need to run automated tests, that involve several machines, or simply if you would like to skip typing in a password on each connection. http://mosermichael.github.io/cstuff/all/projects/2011/07/14/ssh-friends.html http://mosermichael.github.io/cstuff/all/projects/2011/07/14...
- beagle3 12y agoWhile the socks proxy does not require any root (local or remote), it is only useful for programs that support it - which are not many. However, apenwarr's sshuttle https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle is a briliant semi-proxy-semi-vpn solution that, in return for local root and remote python (but not remote root), gives you transparent VPN-style forwarding of TCP connections (and DNS requests if you want). It works ridiculously well. Try it, if you haven't yet.