4 ms·
So, is there a big advantage to running ssh-agent vs unencrypted 0400 keys in your ~/.ssh directory?
by ambrice 12y ago
So, is there a big advantage to running ssh-agent vs unencrypted 0400 keys in your ~/.ssh directory?
- agwa 12y agoYes. ssh-agent prevents non-root users, including the user running ssh-agent[1] from being able to extract the private key. That's much more secure than storing unencrypted keys in ~/.ssh. [1] ssh-agent uses some tricks, like making itself setgid, and/or using prctl(PR_SET_DUMPABLE, 0) on Linux to make its memory undumpable.
- 0x0 12y agoAnd on OSX, it integrates with the keychain as well!
- void-star 12y agoYou're better off not storing your passphrase in the keychain and just typing it in that one first time, though. But it's still marginally better than an unencrypted private key for automation if you need a 100% unattended setup.
- lloeki 12y ago"In the keychain" doesn't necessarily mean in the login keychain. You can create as many user keychains as you want, with different passwords. Also, add the keychain app to your menubar (via preferences) to get a quick way to manually lock one or all keychains (and alternatively, the whole computer).
- Canada 12y agoThat won't prevent your key from being stolen if you leave it on a VM controlled by someone else. Your key belongs on your personal device, and agent forwarding enables you to behave as if your key is everywhere you need it to be.