Re: Keyphrase for the server's secret key

From: Darren Dunham (ddunham_at_redwood.taos.com)
Date: 08/29/04

  • Next message: Triforce: "Cygwin / SSHD - Login issues."
    Date: Sat, 28 Aug 2004 23:15:31 GMT
    
    

    Torsten Bronger <bronger@physik.rwth-aachen.de> wrote:
    > Hallöchen!

    > I'm just curious: I was told that it's very wise to protect one's
    > secret key (being an ssh client) with a key phrase. However, the
    > sshd server also has a secret key. But there is no way to protect
    > it with a similar, is it? So I assume it isn't necessary. But why?

    If a passphrase is used on a key, it has to be entered before it can be
    used. Most folks want the servers to boot unattended. With a
    passphrase on the server key, you would have to type it in before the
    server could use the key.

    Also, a user's key tends to be more mobile. It might be used on less
    well secured machines, or might even be in an NFS exported home
    directory.

    -- 
    Darren Dunham                                           ddunham@taos.com
    Senior Technical Consultant         TAOS            http://www.taos.com/
    Got some Dr Pepper?                           San Francisco, CA bay area
             < This line left intentionally blank to confuse you. >
    

  • Next message: Triforce: "Cygwin / SSHD - Login issues."

    Relevant Pages

    • Re: SSL & Man In the Middle Attack
      ... > it possible for the middle man to intercept all messages from server to me ... server sends client a signed message along with a digital certificate. ... client generates a random secret key, ...
      (comp.security.misc)
    • Authentication Protocol -- Request for Comments
      ... I have developed an authentication protocol using only HMAC tokens. ... AS Auth Server, ... Ks Secret Key Server ... Es Public Entropy Random Seed Server ...
      (sci.crypt)
    • Inescapable public key property of secret key transport?
      ... following two security properties for a secret key transport ... For the purpose of this post, a secret key transport scheme is ... defined as the server processing of a key establishment packet ...
      (sci.crypt)
    • Re: IPSEC Problems
      ... > are able to create a link with my new server, ... > 192.168.245.12 Secret Key ... To unsubscribe, ...
      (freebsd-questions)
    • Re: Password authentication systems
      ... your fast responses. ... Do you need to interoperate, ... with an actual secret key, if you have a way to maintain one. ... intended for a game server ...
      (comp.lang.python)