Problems with options on Authorized_keys file and Public Key

From: b wreath (bearwreath@yahoo.ca)
Date: 03/13/03

  • Next message: snogfest hosebeast: "Re: password-less logon using authorized_keys"
    From: bearwreath@yahoo.ca (b wreath)
    Date: 12 Mar 2003 15:21:09 -0800
    
    

    Hi,

    I am trying to create a passwordless login with a public key that has
    no passphrase. I realize that this has some security issues. I am
    trying
    to reduce the security issues by adding options on my authorized_keys
    file.
    I have appended something like:
    command="/home/breath/etc/localscript",from="myserver.dfs.ca" at the
    front of my public key file (id_rsa.pub) stored at the remote server I
    wish to connect to and I have also renamed id_rsa.pub to be
    authorized_keys.
    (local script just echoes a message)

    I tested this to see if I could enter commands like scp from my
    server.
    scp worked which tells me that the options are not
    restricting the use of the key properly.

    -I am not sure what is wrong. I would appreciate some help on this.
    -Also, it would be nice if someone provided some examples like an
    example
    command="" and then a test to see if the command is working
    then I can see if I am using the correct tests and see if
    I am using the correct syntax.
    -Also, Would this work with command="rsync etc..."?

    thanks very much,
    bwreath


  • Next message: snogfest hosebeast: "Re: password-less logon using authorized_keys"

    Relevant Pages

    • RE: Encryption question
      ... > sender's private key at the message hash. ... >>Alice encrypts her email to Bob using his public key. ... > Security Linux, the comprehensive security solution that combines six ... Protect your network against hackers, viruses, spam and other risks with Astaro Security Linux, the comprehensive security solution that combines six applications in one software solution for ease of use and lower total cost of ownership. ...
      (Security-Basics)
    • Re: passwords
      ... different security domain ... by a public key (that has been registered in lieu of a shared-secret ... both originate as well as validate an authentication ... ... public key can't be used to originate an authentication ... ...
      (alt.computer.security)
    • Re: Elliptic Curve Cryptography algorithm for key exchange
      ... AES can be compromised through the weaker security ... >> your public key cryptography. ... this would mean the large key sizes required to match AES ... > protection with easily crackable pswd-derived AES keys!! ...
      (microsoft.public.platformsdk.security)
    • Re: public key vs passwd authentication?
      ... > I have a client that's turned off public key authentication. ... > examination of the security aspect, it'd make my job a lot easier/ ... http://www.garlic.com/~lynn/aadsm15.htm#2 Is cryptography where security took the wrong branch? ...
      (comp.security.ssh)
    • Re: S/Key better than public key?
      ... > I used to think that public key authorization is the most secure one. ... There is no "most secure" authentication method. ... security policy, and not for another. ...
      (comp.security.ssh)

  • Quantcast