Re: openssh_config problems

From: Richard E. Silverman (res_at_qoxp.net)
Date: 07/25/03

  • Next message: Fluker: "Question about SSH, well duh."
    Date: 25 Jul 2003 04:49:27 -0400
    
    

    >>>>> "JDL" == Jan De Luyck <jdeluyck.no.spam@hou.uwe.spam.bij.u.triennium.com> writes:

        JDL> hello List, I'm looking to implement ssh on our servers (40
        JDL> solaris boxes)

        JDL> Due to architectural reasons I'm currently unable to put my ssh
        JDL> identity keys in $HOME/.ssh - $HOME is a directory that is
        JDL> rdisted over several servers.

    I don't understand your reasoning here. Why is this an impediment?
    Presumably you have one, or a small set, of personal keys, which would be
    the same everywhere.

    But more to the point, why put your private keys on these boxes at all? I
    would keep them on a smaller set of machines I log into directly (e.g. my
    desktop), and place only the public keys on the servers. Use agent
    forwarding if you need transitive access to your keys from there.

    -- 
      Richard Silverman
      res@qoxp.net
    

  • Next message: Fluker: "Question about SSH, well duh."

    Relevant Pages

    • Re: openssh_config problems
      ... > JDL> hello List, I'm looking to implement ssh on our servers (40 ... > JDL> Due to architectural reasons I'm currently unable to put my ssh ... > JDL> rdisted over several servers. ... > Presumably you have one, or a small set, of personal keys, which would be ...
      (comp.security.ssh)
    • Re: Enterprose Manager after user password change
      ... XP client machines with a non-Domain account. ... > registered servers when the user's network password is changed. ... Saving the keys and restoring ... > password should be written to the registry. ...
      (microsoft.public.sqlserver.security)
    • graceful ssh key management
      ... How do I have multiple ssh keys not overwrite each other, ... I have a computer that is a client to a number of different servers. ...
      (SSH)
    • OpenSSH 3.0.1p1 Solaris 2.5 - 8.0 Nightmares occuring
      ... I am having some really bad problems trying to upgrade our servers to ... having all kinds of issues with the keys. ... PS Am purchasing O'reilly's SSH book today, hopefully, it will ...
      (comp.security.ssh)
    • Re: courier imap keys and self-signed ca signing
      ... >> a program to generate keys but not csr's, i'm not sure how to get keys from ... > signed CA from OpenSSL and use it to sign a single cert for all your ... > servers. ... I'm not sure http browsers are aware of that field, ...
      (freebsd-questions)