D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Security and SSH

 

On Fri, 21 Jan 2011, Neil Winchurst wrote:

On 21/01/11 10:00, Philip Hudson wrote:
On 21 Jan, 2011, at 8:49 am, Neil Winchurst wrote:

I think that I would like to understand it all a bit better. I will be
asking for some help on setting it up therefore, thanks Phil.


Cool. The files we'll be dealing with are $HOME/.ssh/config and
(depending on distro) /etc/sshd_config or /etc/ssh/sshd_config. You need
to edit and save the latter with superuser privileges. If you go for
public keys, we'll also be appending keys to $HOME/.ssh/authorized_keys
on the server.

The sshd_config file is liberally commented, but not everything in the
comments is straightforward to understand.

It should be OK to keep this on-list, so long as we don't include
passwords, passphrases and private (not public) keys -- we'll get to
those in a bit -- but anything you're not sure about, take it offline.

I will have more time this afternoon, but to start with, do I need to use SSL/TLS Manager to generate a private key? Is that the first task. If so I must think about a pass phrase. And is it easy to change said pass phrase if I decide to?

I don't know cPanel, however, I suspect that all you need to do is enable SSH, then use SSH (or e.g. Putty from a win box) to connect to the IP address of the server using the same username and password you use for FTP.

Once ssh'd in, you can use the command-line to generate a key and transfer it back to your PC (cut & paste) - if that's what you want to do. You don't need to. I only do it for a small number of hosts where it's convenient to login without a password. (or, where for additional security I've disabled password login)

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq