Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Using SSH around the LAN
Date: Wed, 13 Jul 2016 08:49:12
Message-Id: 2701720.vLVCXgLEGK@peak
In Reply to: Re: [gentoo-user] Using SSH around the LAN by Alan McKinnon
1 On Tuesday 12 July 2016 17:48:33 Alan McKinnon wrote:
2 > On 12/07/2016 17:42, Peter Humphrey wrote:
3 > > Is there a guide to setting up password-less authentication to enable me
4 > > to do this?
5 >
6 > http://www.funtoo.org/Keychain
7
8 Thanks Alan. I don't think it's the one I read before but it looks useful
9 anyway.
10
11 > Note that you, portage and root are 3 different users, so you must make
12 > key pairs for each on each source machine you will ssh from.
13 >
14 > Then you need to add each of those user's public keys to each
15 > destination user's authorized_keys file on each machine you want to ssh to.
16 >
17 > That can be a lot of key copying :-) 3 x 3 x # of machines
18 >
19 > Finally, on each machine you will ssh from and as each user who will do
20 > the ssh'ing, you must run keychain at least once to store the key creds.
21 > They should then persist until reboot, when you must run keychain again
22 > for each user.
23
24 Hmm. I may end up just allowing ssh password authentication and relying on my
25 vDSL router to keep other people's noses out of my business. The portage user
26 can't log in anyway, so its scp-ing and rsyncing would have to be done by
27 root.
28
29 > The idea is that a given user's keychain creds are valid over all that
30 > user's login sessions on a machine. Users cannot share each other's
31 > keychain
32
33 You've given me plenty to think about - thanks again.
34
35 --
36 Rgds
37 Peter

Replies

Subject Author
Re: [gentoo-user] Using SSH around the LAN Mick <michaelkintzios@×××××.com>