Re: openssh_config problems

From: Nico Kadel-Garcia (nkadel_at_verizon.net)
Date: 07/25/03


Date: Fri, 25 Jul 2003 10:48:47 GMT

Richard E. Silverman wrote:

>>>>>>"JDL" == Jan De Luyck <jdeluyck.no.spam@hou.uwe.spam.bij.u.triennium.com> writes:
>
>
> JDL> hello List, I'm looking to implement ssh on our servers (40
> JDL> solaris boxes)
>
> JDL> Due to architectural reasons I'm currently unable to put my ssh
> JDL> identity keys in $HOME/.ssh - $HOME is a directory that is
> JDL> rdisted over several servers.
>
> I don't understand your reasoning here. Why is this an impediment?
> Presumably you have one, or a small set, of personal keys, which would be
> the same everywhere.
>
> But more to the point, why put your private keys on these boxes at all? I
> would keep them on a smaller set of machines I log into directly (e.g. my
> desktop), and place only the public keys on the servers. Use agent
> forwarding if you need transitive access to your keys from there.
>

Amen. I find that putting them on a CD or floppy and using ssh-agent, or
using an *extremely* secure machine for them, allows me to go nab the
keys as needed when online and keep them unavailable when offline.



Relevant Pages

  • Re: openssh_config problems
    ... JDL> solaris boxes) ... JDL> rdisted over several servers. ... Presumably you have one, or a small set, of personal keys, which would be ...
    (comp.security.ssh)
  • openssh_config problems
    ... I'm looking to implement ssh on our servers ... Due to architectural reasons I'm currently unable to put my ssh identity ... I want to put the keys in $HC/.ssh, which is a different path on each ...
    (comp.security.ssh)
  • Re: Enterprose Manager after user password change
    ... XP client machines with a non-Domain account. ... > registered servers when the user's network password is changed. ... Saving the keys and restoring ... > password should be written to the registry. ...
    (microsoft.public.sqlserver.security)
  • graceful ssh key management
    ... How do I have multiple ssh keys not overwrite each other, ... I have a computer that is a client to a number of different servers. ...
    (SSH)
  • OpenSSH 3.0.1p1 Solaris 2.5 - 8.0 Nightmares occuring
    ... I am having some really bad problems trying to upgrade our servers to ... having all kinds of issues with the keys. ... PS Am purchasing O'reilly's SSH book today, hopefully, it will ...
    (comp.security.ssh)