Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Any way to automate login to host and su to root?
Date: Mon, 18 Jul 2022 09:28:40
Message-Id: 3625553.MHq7AAxBmi@poseidon
In Reply to: Re: [gentoo-user] Any way to automate login to host and su to root? by Grant Taylor
1 On Monday, 18 July 2022 08:03:44 CEST Grant Taylor wrote:
2 > On 7/17/22 11:48 PM, J. Roeleveld wrote:
3 > > It could, but that would open up an unsecured key to interception if
4 > > an intermediate host is compromised.
5 >
6 > What are you thinking? -- I've got a few ideas, but rather than
7 > speculating, I'll just ask.
8
9 See below
10
11 > > See previous answer, the agent, as far as I know, will have the keys
12 > > in memory and I haven't seen evidence that it won't provide the keys
13 > > without authenticating the requestor.
14 >
15 > Are you concerned about a rogue requestor on the host where the agent is
16 > running or elsewhere?
17
18 Either on the client where the agent is running, but also on the system I connected to.
19 But, I just noticed the following, which is hopeful, but need to read up on this:
20 https://www.openssh.com/agent-restrict.html[1]
21
22 > > Yes, copy/paste has no issues with multi-page texts. But manually
23 > > reading a long password and copying that over by typing on a keyboard
24 > > when the font can make the difference between "1" (ONE), "l" (small
25 > > letter L) and "|" (pipe- character) and similar characters make it
26 > > annoying to say the least.
27 >
28 > Agreed.
29 >
30 > > Currently, when that comment pops up, the first thing I do is wait
31 > > and wonder why it's asking for it. As all the systems are already
32 > > added to the list.
33 >
34 > Such a pop-up would be a very likely indication of a problem.
35
36 Agreed, which is why I always stop and think when I see that.
37 Usually the answer is: "Oh, yes, I didn't access this host from my laptop yet". But that is usually
38 after the 2nd or 3rd connection attempt with retyping the hostname and verifying the IP-address
39 that is resolved for it first.
40
41 --
42 Joost
43
44 --------
45 [1] https://www.openssh.com/agent-restrict.html

Replies

Subject Author
Re: [gentoo-user] Any way to automate login to host and su to root? Grant Taylor <gtaylor@×××××××××××××××××××××.net>