Re: Permissions on .ssh files Please.



On Mon, Sep 25, 2006 at 11:02:42PM -0600, Reg Clemens wrote:
I know I have a listing somewhere that shows what the permissions should be
on the files in $HOME/.ssh , but cant find it for the life of me.

It's not just that ONE file!

Every single directory in the entire path leading up to ~/.ssh, as well
as the authorized_keys file therein, must NOT have group or world write
permission.

ls -ld / /home /home/you /home/you/.ssh /home/you/.ssh/authorized_keys

If any one of the directories or the file in the output of that command
have group or world write permission (e.g., drwxrwxr-x) then sshd will
refuse to acknowledge the authorized_keys file.

Many Linux distributions include some sort of group-writable /home
directory. This is a frequent cause of problems. People who ONLY
look at ~/.ssh won't understand why their public key auth is failing.



Relevant Pages

  • Convict 1959-0711 / Rosa =?UTF-8?B?TWFyw61hIFJvZHLDrWd1ZXogVG9ycg==?= =?UTF-8?B?YWRv?=
    ... She got on the sky blue boat towards a new life without looking back. ... She didn't wait long to look for work; she liked to be independent and satisfy her desires without asking permission from anyone. ... After, they seemed more like a melodrama, with nostalgia for what was left behind mixed with the asphyxiating smell of bathroom disinfectants. ... She asked herself if she hadn't been too intolerant in judging certain acts of others or if she hadn't known how to defend her rights when she felt cheated. ...
    (soc.culture.cuba)
  • Re: Boots May Be Right
    ... long ago granted myself permission to believe what I choose without ... If their research and opinions are decently documented they can ... If I had not mastered the basics of life I would have been dead long ... the winds have died down sufficiently for me to go outside and shovel ...
    (misc.writing)
  • Re: Help with SBS 2000 Permission/ Exchange
    ... I am most certain this is a permission issue. ... I am being logged onto a temporary profile instead of my default ... administrator account. ... I cant figure out why. ...
    (microsoft.public.windows.server.sbs)
  • Re: Help with SBS 2000 Permission/ Exchange
    ... I am most certain this is a permission issue. ... I am being logged onto a temporary profile instead of my default ... administrator account. ... I cant figure out why. ...
    (microsoft.public.windows.server.sbs)
  • Re: What exactly is MCS?
    ... Consider giving yourself permission to be comfortable in the ... presence of invasive scents. ... invasive scents" any more than someone can give themselves permission ... I'd love to be able to go back to my old life when I didn't have to be ...
    (misc.health.alternative)