OpenSSH ssh-keygen and non-empty passphrase

bnies_at_bluewin.ch
Date: 05/25/05

  • Next message: Rob: "sftp concerns"
    Date: 25 May 2005 07:11:33 -0700
    
    

    Hi,

    Is it possible to configure ssh-keygen that it is not possible to use
    empty passphrases and configure the minimal length of a passphrase?

    Or: As an alternative one can write a wrapper script that checks for
    the passphrase. But ssh-keygen seems only to accept a passphrase as
    command argument and not from standard input. This is unsafe because in
    the moment of generating a new SSH keypair one can see the passphrase
    when doing a 'ps -ef'.

    Reading the new passphrase from standard input or setting global
    passphrase policies for ssh-keygen would be a good feature. Or is it
    somewhere hidden in the code and must be activated at compile time?

    Thanks in advance.

    Regards,
    Bernd


  • Next message: Rob: "sftp concerns"

    Relevant Pages

    • Re: OpenSSH ssh-keygen and non-empty passphrase
      ... > command argument and not from standard input. ... This is unsafe because in ... > the moment of generating a new SSH keypair one can see the passphrase ...
      (comp.security.ssh)
    • Re: ssh-keygen empty passphrase
      ... the command won't read anything from ... standard input. ... "Enter passphrase(empty for no passphrase): ...
      (comp.security.ssh)
    • Re: OpenSSH ssh-keygen and non-empty passphrase
      ... As an alternative one can write a wrapper script that checks for ... But ssh-keygen seems only to accept a passphrase as ... > command argument and not from standard input. ... Depend on the rabbit's foot if you will, but remember, it didn't help the rabbit. ...
      (comp.security.ssh)
    • Re: Partition Encryption
      ... It's very irresponsible to call "not needing to reenter the passphrase ... after suspend to disk" a feature. ... I recommend removing the paragraph ... risk to use suspend to ram/disk, ...
      (comp.os.linux.security)