| ||||||
| 5/17 |
| 2006/5/2-5 [Computer/SW/Security] UID:42892 Activity:nil |
5/2 Okay, I think I get it now. If I want password-less login to
soda, then I need to do the whole generating the public and private
keys which requires a pass phrase, if I can put up with entering
my unix password every time in SSH or PUTTY, then I don't need
to do the whole ssh-keygen stuff. Is it correct?
\_ Yes. But if you go password-less, then if soda is compromised
again, you won't need to change your unix password.
\_ why is that? if soda is compromised then they have access
to the unix password too.
\_ Not if you didn't type it in while soda was compromised. -tom
\_ Unless it was cracked, which basically depends only on
how motivated the attacker is. -gm
\_ This is why a couple of soda users choose not to have
passwords at all -- they have "*" for their password
in /etc/shadow, so ssh keys are the only way they can
log in. For those users, an attacker who gets soda's
password file won't have anything to crack. --mconst
\_ how do you put * in /etc/shadow? I can't even
view it? so if I don't want to use unix password,
I need to ssh-keygen on my client server, then copy
the generated public key to soda under .ssh/ folder?
I should not copy my private key on soda though, right?
\_ Unfortunately, it's not possible for you to do
this yourself. If you really want to have no
password, mail root and we can remove it for
you -- but before you do that, you might want
to try just setting your password to something
random and not using it for a while. This will
give you a chance to get used to ssh keys and
see how you like them, and if anything goes
wrong with your ssh keys, you'll be able to log
in with your password and fix them. And yes,
your ssh-keygen stuff is exactly right. You
didn't mention this, but when you put the public
key on soda, you need to put it in a file named
.ssh/authorized_keys. --mconst
\_ thank you bery much! this helped alot in clearing
out my confusions.
\_ I was told because of the comprise, my ssh private key may be
stolen as well, but how is that possible? I thought the ssh
private key is on the client host, not on the server host (i.e.
http://csua.berkeley.edu)?
\_ Some people put their private keys on soda (with a passphrase,
I would hope). If you did, then both your private key and your
passphrase may have been stolen. If you didn't store your private
key on soda, you should be fine. -gm
\_ they put their private keys on soda, is it because they want
to use soda as a client to a different server?
\_ Exactly.
\_ the private key would be under .ssh/ right? |
| 5/17 |
|
| csua.berkeley.edu Science Undergraduate Association The Computer Science Undergraduate Association is dedicated to representing the undergraduate Computer Science student body and associates to the University of California at Berkeley, its representatives, and other related organizations; Our office is located in 343 Soda Hall, located at the corner of Hearst & LeRoy. May___| |May, 2004 | |_S___M___T___W___T___F___S_| | |1 | ||___| |2 |3 |4 |5 |6 |7 |8 | |___|___|___|___|___|___|___| |9 |10 |11 |12 |13 |14 |15 | |___|___|___|___|___|___|___| |16 |17 |18 |19 |20 |21 |22 | |___|___|___|___|___|___|___| |23 |24 |25 |26 |27 |28 |29 | |___|___|___|___|___|___|___| |30 |31 | | |___|___|| Calendar of Events Mon, May 3rd, (6:00 PM) General Meeting/Officer Elections Announcements: * CSUA t-shirts are now available in the office (343 Soda) for $12 each. Baby-doll cuts also available. View the design on front and back. The CSUA Mentoring Program is calling for new students to sign up to be mentored. Register to find out more information about this free program at the mentoring website. Members interested in mentoring should contact jhs as soon as possible. CSUA Officer Meetings: Politburo meetings for Spring 2004 are scheduled for every Monday at 6pm in 337 Soda Hall. New members always welcome. Help Sessions are being offered, open especially to new students. The topics, times, and locations are listed here. We just made a Costco run. If you don't know what this means, stop by 343 Soda to find out. The Constitution has been amended. Many thanks to AMD and the TDA Project. Secure remote logins require either SSH ( Java Client) or S/KEY ( Java Client). User Policy - The Rules * Frequently Asked Questions about the CSUA and Soda * CSUA Constitution * Message of the Day - Including downtime announcements * CSUA Library * CSUA Encyclopedia * Membership application form, in PDF, TeX, DVI, and Postscript. The Mentoring Program * Prospective LSCS Mailing List. |