<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: keychain: Set Up Secure Passwordless SSH Access For Backup Scripts</title> <atom:link href="http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/feed/" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/</link> <description>Every answer asks a more beautiful question.</description> <lastBuildDate>Fri, 10 Feb 2012 19:55:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: milan</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-55525</link> <dc:creator>milan</dc:creator> <pubDate>Fri, 11 Feb 2011 05:43:33 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-55525</guid> <description>Hi
good post .i was wondering,what if i lost password in this case.</description> <content:encoded><![CDATA[<p>Hi</p><p>good post .i was wondering,what if i lost password in this case.</p> ]]></content:encoded> </item> <item><title>By: Halil</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-54897</link> <dc:creator>Halil</dc:creator> <pubDate>Fri, 14 Jan 2011 20:25:21 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-54897</guid> <description>I still receive :
Error:Permission denied, please try again.
Permission denied, please try again.
Permission denied (publickey,password).
rsync: connection unexpectedly closed (0 bytes received so far) [sender]
rsync error: unexplained error (code 255) at io.c(454) [sender=2.6.9]</description> <content:encoded><![CDATA[<p>I still receive :<br
/> Error:Permission denied, please try again.<br
/> Permission denied, please try again.<br
/> Permission denied (publickey,password).<br
/> rsync: connection unexpectedly closed (0 bytes received so far) [sender]<br
/> rsync error: unexplained error (code 255) at io.c(454) [sender=2.6.9]</p> ]]></content:encoded> </item> <item><title>By: Philip Hands</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-50192</link> <dc:creator>Philip Hands</dc:creator> <pubDate>Tue, 19 Oct 2010 05:22:04 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-50192</guid> <description>An &lt;a href=&quot;http://wiki.hands.com/howto/passphraseless-ssh/&quot; rel=&quot;nofollow&quot;&gt;alternative approach&lt;/a&gt; is to lock down passphraseless keys so they do exactly and only what they need, so that an attacker doesn&#039;t actually get anything useful even if they do manage to steal the key.
The thing about needing to be an uber-hacker to get at the keys in memory is a resort to security through obscurity, which will encourage sloppy thinking about the real issue, which is that you in effect have passwordless keys on the system, so you should make sure that those keys only get to do what you want and nothing more.  As shown in the above link, it&#039;s possible to lock it down to the point that the keys only open up the tiny crack of read-only access from the right IP address, so an attacker really gets nothing from having such keys.  I seriously doubt anyone using this keychain approach will bother with the &lt;code&gt;command=&lt;/code&gt; bit in their &lt;code&gt;authorised_keys&lt;/code&gt; file, which means that they&#039;re giving an attacker much more if there is a break-in.
Oh, and you should be setting &lt;code&gt;PermitRootLogin&lt;/code&gt; to &lt;code&gt;without-password&lt;/code&gt;, or &lt;code&gt;no&lt;/code&gt; (rather than yes)</description> <content:encoded><![CDATA[<p>An <a
href="http://wiki.hands.com/howto/passphraseless-ssh/" rel="nofollow">alternative approach</a> is to lock down passphraseless keys so they do exactly and only what they need, so that an attacker doesn&#8217;t actually get anything useful even if they do manage to steal the key.</p><p>The thing about needing to be an uber-hacker to get at the keys in memory is a resort to security through obscurity, which will encourage sloppy thinking about the real issue, which is that you in effect have passwordless keys on the system, so you should make sure that those keys only get to do what you want and nothing more.  As shown in the above link, it&#8217;s possible to lock it down to the point that the keys only open up the tiny crack of read-only access from the right IP address, so an attacker really gets nothing from having such keys.  I seriously doubt anyone using this keychain approach will bother with the <code>command=</code> bit in their <code>authorised_keys</code> file, which means that they&#8217;re giving an attacker much more if there is a break-in.</p><p>Oh, and you should be setting <code>PermitRootLogin</code> to <code>without-password</code>, or <code>no</code> (rather than yes)</p> ]]></content:encoded> </item> <item><title>By: nigg belamps</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-50127</link> <dc:creator>nigg belamps</dc:creator> <pubDate>Fri, 15 Oct 2010 14:06:24 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-50127</guid> <description>hahaha root@pee ... thats hot</description> <content:encoded><![CDATA[<p>hahaha root@pee &#8230; thats hot</p> ]]></content:encoded> </item> <item><title>By: Neil Jensen</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-43890</link> <dc:creator>Neil Jensen</dc:creator> <pubDate>Wed, 30 Sep 2009 04:43:23 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-43890</guid> <description>Hi, I have been trying to get rsnapshot to run with keychain under cron for root when logged out.
For me adding
source /root/.keychain/-sh
to cmd_preexec in the rsnapshot.conf did not work
What has finally worked for me which works remotely and locally is:
under cron run a command pointing to shell scripts for hourly daily weekly and monthly rsnapshots
my script is for hourly backups is hourly.sh
#!/bin/bash
ENV=/root/.bashrc
source /root/.keychain/-sh
rsnapshot hourly
the reason why this was needed is because cron for ssh doesn&#039;t enter a shell to perform it&#039;s function, so before rsnapshot begins you must point the process into a shell or you get an annoying and failing error 255 stating rsync couldn&#039;t ssh(or something like that).  Then just re comment the cmd_preexec line in the rsnapshot.conf</description> <content:encoded><![CDATA[<p>Hi, I have been trying to get rsnapshot to run with keychain under cron for root when logged out.</p><p>For me adding<br
/> source /root/.keychain/-sh<br
/> to cmd_preexec in the rsnapshot.conf did not work<br
/> What has finally worked for me which works remotely and locally is:<br
/> under cron run a command pointing to shell scripts for hourly daily weekly and monthly rsnapshots</p><p>my script is for hourly backups is hourly.sh<br
/> #!/bin/bash<br
/> ENV=/root/.bashrc<br
/> source /root/.keychain/-sh<br
/> rsnapshot hourly</p><p>the reason why this was needed is because cron for ssh doesn&#8217;t enter a shell to perform it&#8217;s function, so before rsnapshot begins you must point the process into a shell or you get an annoying and failing error 255 stating rsync couldn&#8217;t ssh(or something like that).  Then just re comment the cmd_preexec line in the rsnapshot.conf</p> ]]></content:encoded> </item> <item><title>By: Heikki Orsila</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-42730</link> <dc:creator>Heikki Orsila</dc:creator> <pubDate>Sun, 26 Jul 2009 16:47:58 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-42730</guid> <description>ssh-copy-id command is an easier way to copy your public key to a server:
ssh-copy-id -i ~/.ssh/id_dsa.pub user@host</description> <content:encoded><![CDATA[<p>ssh-copy-id command is an easier way to copy your public key to a server:</p><p>ssh-copy-id -i ~/.ssh/id_dsa.pub user@host</p> ]]></content:encoded> </item> <item><title>By: Lexsys</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-42137</link> <dc:creator>Lexsys</dc:creator> <pubDate>Fri, 19 Jun 2009 08:11:21 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-42137</guid> <description>I have a problem with my rsnapshot configuration. If I enter your command into rsnapshot.conf file, I get an error:
&lt;code&gt;ERROR: cmd_preexec source /home/lexsys/.keychain/dev-server-sh - &quot;source&quot; is not executable or can&#039;t be found. Please use an absolute path. &lt;/code&gt;
I created an executable 1.sh, placed the command into this file and write in rsnapshot.conf:
&lt;code&gt;cmd_preexec /root/1.sh&lt;/code&gt;
Everything works fine.</description> <content:encoded><![CDATA[<p>I have a problem with my rsnapshot configuration. If I enter your command into rsnapshot.conf file, I get an error:<br
/> <code>ERROR: cmd_preexec source /home/lexsys/.keychain/dev-server-sh - "source" is not executable or can't be found. Please use an absolute path. </code></p><p>I created an executable 1.sh, placed the command into this file and write in rsnapshot.conf:<br
/> <code>cmd_preexec /root/1.sh</code></p><p>Everything works fine.</p> ]]></content:encoded> </item> <item><title>By: Ulver</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-41969</link> <dc:creator>Ulver</dc:creator> <pubDate>Mon, 08 Jun 2009 13:11:31 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-41969</guid> <description>another interesting way to protect ssh,  is chroot them, but it depends of the particulary needs of each one</description> <content:encoded><![CDATA[<p>another interesting way to protect ssh,  is chroot them, but it depends of the particulary needs of each one</p> ]]></content:encoded> </item> <item><title>By: Colin</title><link>http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/#comment-41942</link> <dc:creator>Colin</dc:creator> <pubDate>Sat, 06 Jun 2009 22:20:56 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3938#comment-41942</guid> <description>I think I found a typo.
&quot;OpenSSH sshd server offers two additional option to protect abuse of keys. First, make sure root login disabled (PermitRootLogin yes).&quot;</description> <content:encoded><![CDATA[<p>I think I found a typo.<br
/> &#8220;OpenSSH sshd server offers two additional option to protect abuse of keys. First, make sure root login disabled (PermitRootLogin yes).&#8221;</p> ]]></content:encoded> </item> </channel> </rss>
