Solved

SSH Keys

Posted on 2014-09-05
11
281 Views
Last Modified: 2014-09-20
I followed the steps here and now I am locked out:

https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys--2

In putty do I need to some how upload my key file? What did I do wrong?

I am getting access denied when logging in as root.
0
Comment
Question by:Starquest321
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
11 Comments
 

Author Comment

by:Starquest321
ID: 40307041
What seems to mess me up is this step:

PermitRootLogin without-password

I changed the file from the orignal:
PermitRootLogin yes

I am trying to understand: do I need a saved copy of the public key on my (windows based ) laptop?
0
 
LVL 4

Accepted Solution

by:
mbertl earned 84 total points
ID: 40307235
No, the key will be stored after first login. After that, login works normal.
0
 

Author Comment

by:Starquest321
ID: 40307501
So when I do this on the cent os box:
ssh-copy-id user@123.45.56.78

I can "ADD" approved "users" and "ips" for login? Is that how this works?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:Starquest321
ID: 40307502
Also during the setup in their instructions I added a passpharse. How can I remove that?
0
 
LVL 38

Assisted Solution

by:Gerwin Jansen, EE MVE
Gerwin Jansen, EE MVE earned 333 total points
ID: 40307628
>> I added a passpharse. How can I remove that?
You can't remove that passphrase, it is to protect your private key. That's what it is meant for.

Can you logon as a normal user? If so, do that, then su to root and undo that last PermitRootLogin change you made. Restart sshd and test with another session if you can logon now.

When changing sshd config, always keep the session open that you used to change the configuration. So if things go wrong you can undo the changes.
0
 

Author Comment

by:Starquest321
ID: 40307635
I undid that last PermitRootLogin .. and I can login fine. Does that still mean I have SSH enabled? How can I check?
0
 
LVL 38

Assisted Solution

by:Gerwin Jansen, EE MVE
Gerwin Jansen, EE MVE earned 333 total points
ID: 40307650
>> How can I check?

You logon like this:

ssh your_user@your_host

and then you get a prompt on your_host

all without typing a password.
0
 
LVL 38

Assisted Solution

by:Gerwin Jansen, EE MVE
Gerwin Jansen, EE MVE earned 333 total points
ID: 40307652
You are using PuTTY right? Are you running Putty Agent (Pagent) as well?
0
 

Author Comment

by:Starquest321
ID: 40307669
I am running Putty. What is Putty Agent ?
0
 
LVL 38

Assisted Solution

by:Gerwin Jansen, EE MVE
Gerwin Jansen, EE MVE earned 333 total points
ID: 40307723
Putty Agent is installed with Putty. You use the agent to load your private ssh key(s) and enter the passphrase once. Then you configure Putty to use ssh keys (pointing to your private key) and putty will see that the agent has already loaded the private key. That way you only have to enter the passphrase once and just use putty (saved) sessions to connect to your hosts.
0
 
LVL 29

Assisted Solution

by:serialband
serialband earned 83 total points
ID: 40315466
If you use pageant.exe (Putty Agent), you'll be able to cache the key's passphrase and key your private keys loaded, until you restart pageant, usually when you reboot.
http://winscp.net/eng/docs/ui_pageant  <-- it's the same for putty & winscp.

You could also attach the key to your putty profile.  In the Putty Configuration, under the Connection --> SSH --> Auth, there's a place to attach your private key file.  You can save the profile.  This will load your key with each connection, but you'll have to enter a passphrase each time  http://www.howtoforge.com/ssh_key_based_logins_putty_p3

If you want to change your passphrase, you'll need to use puttygen.exe.  Load the private key.  Enter the current passphrase.  Then in the window change the Key Passphrase and Confirm.  You can also remove the passphrase, by setting it to a blank, but I don't recommend it.  It's much, much better to set a passphrase and use pageant.exe to keep your private key protected.

Make sure you get the putty "suite" either in the zip file or the exe installer.  I use the zip file so I can put it where I want and I don't need administrator permissions to "install" it.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question