RE: remote ssh for root

daniel.engelsen_at_caremark.com
Date: 05/09/05

  • Next message: theta_at_netwalk.com: "Re: Bothersome public key SCP implementations.."
    To: Mark Senior <Mark.Senior@gov.ab.ca>
    Date: Mon, 9 May 2005 08:45:31 -0700
    
    

    I was playing around with that, but I really don't want to limit the
    commands that may be run as root from this trusted host. Is there a way to
    say ALL commands like there is in sudo?

    Thanks,
    Dan

                                                                                                                             
                  Mark Senior
                  <Mark.Senior@gov.ab.ca> To: Daniel Engelsen/PCSHS@PCSHS
                                                      cc: secureshell@securityfocus.com
                  05/09/2005 08:32 AM Subject: RE: remote ssh for root
                                                                                                                             
                                                                                                                             

    OK, I see what you mean. How about this - don't know if it exactly
    meets what you need, but it should get you close:

    If you're using the openssh 4 ssh server (and this is likely present in
    earlier versions, I haven't checked), set PermitRootLogin to
    "forced-commands-only". This allows root login with public key
    authentication only, and only when a specific command has been specified
    for execution.

    Then, make a keypair for root, and put the private key only on the one
    trusted admin box (with appropriate. Add to the start of the relevant
    line in .ssh/authorized_keys2 file the limitation:
    from="trustedhost.my.domain"

    Optionally, you can apply other limits to the use of the key you've
    created. For example, limit the command(s) that can be run with that
    key, by adding
    command="/path/to/command"
    to the start of the relevant line of root's .ssh/authorized_keys2 file

    see the section AUTHORIZED_KEYS FILE FORMAT in the sshd manpage for the
    list of possibilities.

    Hope that helps
    Mark

    > -----Original Message-----
    > From: daniel.engelsen
    > Sent: May 9, 2005 08:51
    > To: Mark Senior
    > Subject: RE: remote ssh for root
    >
    >
    > I want to have one host that is trusted by the many hosts.
    > From this host, I want to be able to perform a remote ssh to
    > the many boxes as root; however, I do not want to allow
    > direct root login on any of the servers.
    > If you want to be root, I want the user to have to su to the root id.
    > Also, I do not want to limit what comamnds I can run as root
    > on these boxes from this trusted host.
    >
    > Thanks,
    > Dan
    >
    >
    >
    > Mark Senior
    > To: Daniel Engelsen
    > Subject: RE: remote ssh for root
    >
    >
    >
    > I'm sorry, could you clarify what you mean exactly? I'm not
    > sure what you mean, to ssh as root, without logging in as
    > root via ssh.
    >
    > I suppose just using su or sudo wouldn't cut it?
    >
    > Thanks
    > Mark
    >
    >
    >
    > > -----Original Message-----
    > > From: daniel.engelsen
    > > Sent: May 6, 2005 10:22
    > > To: secureshell@securityfocus.com
    > > Subject: remote ssh for root
    > >
    > > I would like to setup a trusted host that utilizes ssh;
    > however, I do
    > > not want root to be loginable. If I set PermitRootLogin to
    > no, then
    > > the remote ssh function stops as well. Does anyone know of
    > a way to
    > > be able to do remote ssh's as root without allowing root to
    > be able to
    > > login?
    > >
    > > I am using AIX versions 5.1, 5.2, and 5.3, and we are running ssh
    > > versions
    > > 3.6 and 3.8.
    > >
    > > Any ideas would be greatly appreciated.
    > >
    > > Thanks,
    > >
    > >
    > >
    >

    This email and any files transmitted with it are confidential and intended
    solely for the use of the individual or entity to whom they are addressed.
    If you have received this email in error please notify the system manager.
    This message contains confidential information and is intended only for the
    individual named. If you are not the named addressee you should not
    disseminate, distribute or copy this e-mail.

    This email and any files transmitted with it are confidential and intended
    solely for the use of the individual or entity to whom they are addressed.
    If you have received this email in error please notify the system manager.
    This message contains confidential information and is intended only for the
    individual named. If you are not the named addressee you should not
    disseminate, distribute or copy this e-mail.


  • Next message: theta_at_netwalk.com: "Re: Bothersome public key SCP implementations.."

    Relevant Pages

    • Re: I am having serious difficulty getting host based authenication working with ssh
      ... localhost and then think about host to host? ... [root@mandrake root]# echo "IgnoreRhosts no ... the server I was going to ssh into using ... RedHat servers tend to come with sshd already up and running by default. ...
      (SSH)
    • Re: How can I configure to run as root all the time ?
      ... Thanks for responding to my query related to SSH. ... NCP1 is a host with some defined IP address like 10.1.1.201. ... I want to run ssh/scp as root because the keys will be generated by ...
      (comp.security.ssh)
    • User Mode Linux = Network Problem
      ... For UML, root filesystem is Debian 3.0, ip adress 192.168.1.101, ... On the host: ... Initializing software serial port version 1 ... Configuring network interfaces: done. ...
      (comp.os.linux.networking)
    • User Mode Linux = Network Failed !
      ... For UML, root filesystem is Debian 3.0, ip adress 192.168.1.101, ... On the host: ... Initializing software serial port version 1 ... Configuring network interfaces: done. ...
      (comp.os.linux.development.system)
    • Re: Anglo-Saxon Plant-Name Survey
      ... find a host they quickly die; if they do find a host ... Whether they used the 'root' may be a matter of definition: ... See e.g. this real Broomrape http://tinyurl.com/ndooo ... how about the ground seeds and we are ...
      (soc.history.medieval)