Solved

SSH Keys

Posted on 2014-09-05
11
268 Views
Last Modified: 2014-09-20
I followed the steps here and now I am locked out:

https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys--2

In putty do I need to some how upload my key file? What did I do wrong?

I am getting access denied when logging in as root.
0
Comment
Question by:Starquest321
11 Comments
 

Author Comment

by:Starquest321
ID: 40307041
What seems to mess me up is this step:

PermitRootLogin without-password

I changed the file from the orignal:
PermitRootLogin yes

I am trying to understand: do I need a saved copy of the public key on my (windows based ) laptop?
0
 
LVL 4

Accepted Solution

by:
mbertl earned 84 total points
ID: 40307235
No, the key will be stored after first login. After that, login works normal.
0
 

Author Comment

by:Starquest321
ID: 40307501
So when I do this on the cent os box:
ssh-copy-id user@123.45.56.78

I can "ADD" approved "users" and "ips" for login? Is that how this works?
0
 

Author Comment

by:Starquest321
ID: 40307502
Also during the setup in their instructions I added a passpharse. How can I remove that?
0
 
LVL 37

Assisted Solution

by:Gerwin Jansen
Gerwin Jansen earned 333 total points
ID: 40307628
>> I added a passpharse. How can I remove that?
You can't remove that passphrase, it is to protect your private key. That's what it is meant for.

Can you logon as a normal user? If so, do that, then su to root and undo that last PermitRootLogin change you made. Restart sshd and test with another session if you can logon now.

When changing sshd config, always keep the session open that you used to change the configuration. So if things go wrong you can undo the changes.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:Starquest321
ID: 40307635
I undid that last PermitRootLogin .. and I can login fine. Does that still mean I have SSH enabled? How can I check?
0
 
LVL 37

Assisted Solution

by:Gerwin Jansen
Gerwin Jansen earned 333 total points
ID: 40307650
>> How can I check?

You logon like this:

ssh your_user@your_host

and then you get a prompt on your_host

all without typing a password.
0
 
LVL 37

Assisted Solution

by:Gerwin Jansen
Gerwin Jansen earned 333 total points
ID: 40307652
You are using PuTTY right? Are you running Putty Agent (Pagent) as well?
0
 

Author Comment

by:Starquest321
ID: 40307669
I am running Putty. What is Putty Agent ?
0
 
LVL 37

Assisted Solution

by:Gerwin Jansen
Gerwin Jansen earned 333 total points
ID: 40307723
Putty Agent is installed with Putty. You use the agent to load your private ssh key(s) and enter the passphrase once. Then you configure Putty to use ssh keys (pointing to your private key) and putty will see that the agent has already loaded the private key. That way you only have to enter the passphrase once and just use putty (saved) sessions to connect to your hosts.
0
 
LVL 27

Assisted Solution

by:serialband
serialband earned 83 total points
ID: 40315466
If you use pageant.exe (Putty Agent), you'll be able to cache the key's passphrase and key your private keys loaded, until you restart pageant, usually when you reboot.
http://winscp.net/eng/docs/ui_pageant  <-- it's the same for putty & winscp.

You could also attach the key to your putty profile.  In the Putty Configuration, under the Connection --> SSH --> Auth, there's a place to attach your private key file.  You can save the profile.  This will load your key with each connection, but you'll have to enter a passphrase each time  http://www.howtoforge.com/ssh_key_based_logins_putty_p3

If you want to change your passphrase, you'll need to use puttygen.exe.  Load the private key.  Enter the current passphrase.  Then in the window change the Key Passphrase and Confirm.  You can also remove the passphrase, by setting it to a blank, but I don't recommend it.  It's much, much better to set a passphrase and use pageant.exe to keep your private key protected.

Make sure you get the putty "suite" either in the zip file or the exe installer.  I use the zip file so I can put it where I want and I don't need administrator permissions to "install" it.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
This article will explain how to establish a SSH connection to Ubuntu through the firewall and using a different port other then 22. I have set up a Ubuntu virtual machine in Virtualbox and I am running a Windows 7 workstation. From the Ubuntu vi…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now