PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > comp.security.ssh > using ssh-keygen to create identical keys
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.security.ssh SSH secure remote login and tunneling tools.

using ssh-keygen to create identical keys

Réponse
 
LinkBack Outils de la discussion
Vieux 30/10/2006, 18h21   #1
markryde@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut using ssh-keygen to create identical keys

Hello,
I have 5 clients which are connected to three server; this network is
for testing and
it not (AND WILL NOT!) be connected to the internet.
Now: becuase this is for testing, some machines are dual boot; also
quite frequently we
install OS on these machines. Theses machines have flavors of linux,
and there is also solaris.
My question is: we do work a lot with ssh.
If on the client side you run : ssh-keygen -t rsa
it generates 2 files:
id_rsa id_rsa.pub
then if you copy id_rsa.pub to the server renaming it to
authorized_keys2
(no need to restart the ssh daemon on the server!), than next time you
will run ssh from a client to a server than it will connect directly,
without need for a password.


Is there a way that all these clients will have the same key?
(so that on the server, a certain, common authorized_keys2 file will be
used, hopefully
with only one line).
Or is there some other way to cause all the clients to be able to
connect without a password
to all the servers ?

As I said, there is no fear of being attacked from outside as this net
is isoalted from
the outer world.
Regard,
MR

  Réponse avec citation
Vieux 30/10/2006, 18h59   #2
Chuck
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: using ssh-keygen to create identical keys

markryde@gmail.com wrote:
> Hello,
> I have 5 clients which are connected to three server; this network is
> for testing and
> it not (AND WILL NOT!) be connected to the internet.
> Now: becuase this is for testing, some machines are dual boot; also
> quite frequently we
> install OS on these machines. Theses machines have flavors of linux,
> and there is also solaris.
> My question is: we do work a lot with ssh.
> If on the client side you run : ssh-keygen -t rsa
> it generates 2 files:
> id_rsa id_rsa.pub
> then if you copy id_rsa.pub to the server renaming it to
> authorized_keys2
> (no need to restart the ssh daemon on the server!), than next time you
> will run ssh from a client to a server than it will connect directly,
> without need for a password.
>
>
> Is there a way that all these clients will have the same key?
> (so that on the server, a certain, common authorized_keys2 file will be
> used, hopefully
> with only one line).
> Or is there some other way to cause all the clients to be able to
> connect without a password
> to all the servers ?
>
> As I said, there is no fear of being attacked from outside as this net
> is isoalted from
> the outer world.
> Regard,
> MR
>


Yes there is a way. You generate the keys on one machine and copy them
to all the others. I would not do it though. I think it's generally a
good practice for each person to have their own keypair.

Also do not copy the public key to authorized_keys2. That overwrites it.
Use authorized_keys (keys2 is obsolete) instead and concatenate the keys
to the file, one line per key. This is how authorized_keys is designed
to work. It holds multiple keys, not just one.
  Réponse avec citation
Vieux 30/10/2006, 21h40   #3
Richard E. Silverman
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: using ssh-keygen to create identical keys


You can set up hostbased authentication for the network.

- Richard
  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 02h21.


Édité par : vBulletin® version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,11445 seconds with 11 queries