Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #235857

Re: passwordless SSH

From Frank Pikelner <frank.pikelner@gmail.com>
Newsgroups linux.debian.user
Subject Re: passwordless SSH
Date 2021-06-03 23:30 +0200
Message-ID <Cm34B-6cu-1@gated-at.bofh.it> (permalink)
References <CkdB7-5D3-3@gated-at.bofh.it> <CkfWh-6U1-1@gated-at.bofh.it> <Cm2UV-69u-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

It is much better to use SSH certificates, not a great deal of extra work,
but well worth it. Simplifies management and works well for automation.

Best,

Frank

On Thu, Jun 3, 2021 at 5:15 PM David Wright <deblis@lionunicorn.co.uk>
wrote:

> On Sat 29 May 2021 at 18:25:50 (-0400), Bob Weber wrote:
>
> > Now follow the instructions at:
> >
> > https://linuxize.com/post/how-to-setup-passwordless-ssh-login/
> >
> > You will need to follow those instructions for each linux server you
> > want to backup.  The .ssh directory will be under the directory listed
> > in the passwd file (/var/lib/backuppc).? DO NOT USE A PASSWORD TO
> > create the key pair files! They should go into the
> > /var/lib/backuppc/.ssh directory (only do this ONCE!).  In step 03.
> > the username should be root@ip-address (you will need root access on
> > that machine to backup all files from the backuppc user on the
> > backuppc server).  In step 04 you should be able to "ssh
> > root@ip-address" without a password.
>
> I do this as a matter of course when I set up my machines …
>
> > THESE COMMANDS ARE RUN ON EACH SERVER TO BE BACKED UP.
>
> … (not the backuppc stuff, but just the passwordless login) …
>
> > If yyou can't "ssh root@ip-address" without a password you may also
> need the line
> >
> > "PermitRootLogin yes"
> >
> > in the /etc/ssh/sshd_config file on each server to be backed up.
>
> I avoid this wrinkle with a trick that's especially simple when it's
> done first thing after installation (but it's easy at any time).
>
> On machine A:
>
>   # ssh-copy-id -i ~/.ssh/id_rsa.pub <sysadminuser>@hostB
>
> where the sysadminuser¹ is as yet unconfigured for passwordless
> login by ssh. On machine B, as sysadminuser:
>
>   $ /bin/su -
>   # mv -i /home/<sysadminuser>/.ssh/authorized_keys /root/.ssh/
>   # chown 0.0 /root/.ssh/authorized_keys
>
> If sysadminuser already had some keys in authorized_keys,
> then root will need to edit the key from the last line of
> /home/<sysadminuser>/.ssh/authorized_keys rather than just
> moving the file (and make sure you don't leave behind a
> backup in /home/<sysadminuser>/.ssh/authorized_keys~).
>
> Alternatively, you can move sysadminuser's authorized_keys
> out of the way while you type the lines shown above, and then
> move it back. (Stay logged in to sysadminuser while you do this.)
>
> > If you want to you can follow the instructions at "Disabling SSH
> > Password Authentication".  Be very careful to follow the instructions
> > closely.  These are not needed to get backuppc running!  You will need
> > to be able to sudo into root from an unprivileged user to get root
> > access so be VERY careful to follow the instructions.
>
> ¹ I'm assuming root and sysadminuser are the same person, and others
>   don't (yet) have access to the machine.
>
> Cheers,
> David.
>
>

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

passwordless SSH "Gary L. Roach" <garyroach719@gmail.com> - 2021-05-29 22:20 +0200
  Re: passwordless SSH Bob Weber <bob2969685@gmail.com> - 2021-05-30 00:50 +0200
    Re: passwordless SSH David Wright <deblis@lionunicorn.co.uk> - 2021-06-03 23:20 +0200
      Re: passwordless SSH Frank Pikelner <frank.pikelner@gmail.com> - 2021-06-03 23:30 +0200
        Re: passwordless SSH David Wright <deblis@lionunicorn.co.uk> - 2021-06-04 04:30 +0200

csiph-web