How To Set Up OpenSSH Public Key Authentication
Secure Shell or SSH is a network protocol that allows data to be exchanged using a secure channel between two networked devices. Used primarily on GNU/Linux and Unix based systems to access shell accounts, SSH was designed as a replacement for Telnet and other insecure remote shells.
Before we start, make sure your computer has a SSH client installed and the remote Linux system has SSH installed and sshd running.
1. Generating RSA key
You will need to generate the local RSA key by running the following command:
# ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa):
(It's safe to press enter here, as the /root/.ssh is the default and recommended directory to hold the RSA file.)
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
The password you enter here will need to be entered every time you use the RSA key. You can set NO passphrase by pressing Enter but it's not recommended (you can change the passhrase later with "ssh-keygen -p" command).
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
2. Copying the public key to remote system
Once the public key has been generated, it's time to upload it on any Linux systems you usually log into. It's recommended you use scp as the file transfer utility:
# scp .ssh/id_rsa.pub username@ipaddress:~
This command will copy the id_rsa.pub file in the $HOME directory of the remote system. For instance, if you used root as the username, the file will be found in the /root directory and if you used a normal user, the file will be in the /home/username directory.
3. Enabling ssh-key authentication
Next, connect to the remote host through SSH, with the username you used in the step above. RSA authentication won't be available just yet, so you'll have to use the old method to login.
Once you are connected, add the new hostkey to the file /root/.ssh/authorized_keys or /home/username/.ssh/authorized_keys. If the .ssh directory doesn't exist, create it.
# cd $HOME
# cat id_rsa.pub >> .ssh/authorized_keys
This will add the contents of id_rsa.pub file to the authorized_keys file.
Now you have to enable key authentication in sshd_config. Edit /etc/ssh/sshd_config and uncomment or add the following lines
RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
and restart the sshd service.
To test the RSA authentication, initiate a SSH connection from to one of the Linux systems:
# ssh username@ipaddress
If everything worked out well, you should be either asked for the passpharase (if you entered one), or get directly logged in. If you are prompted for the ssh password or get an error message, retry the above command using -v in order to turn verbose mode on and to be able to track down and correct the problem.
If everything is OK, you should disable password authentication for secirty reasons.
To disable password authentication on the remote host you need to uncomment or add
PasswordAuthentication no
UsePAM no
then restart sshd service.
Print This PostSubscribe
Calendar
M | T | W | T | F | S | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | 4 | 5 | ||
6 | 7 | 8 | 9 | 10 | 11 | 12 |
13 | 14 | 15 | 16 | 17 | 18 | 19 |
20 | 21 | 22 | 23 | 24 | 25 | 26 |
27 | 28 | 29 | 30 | 31 |
Polls
Quote of the day
- Winston Churchill -
Recent Posts
- Ubuntu: How to install the Classic Desktop in Ubuntu 11.10 (Oneiric Ocelot)
- FreeBSD: How to set up an UPnP Internet Gateway Device (IGD) with MiniUPnP and FreeBSD 9.0
- Ubuntu: How to build and install Linksys AE1000 Wireless-N linux driver on Ubuntu 11.10
- FreeBSD: How to Install and Configure a PPTP VPN server with mpd5 on FreeBSD 8.2
- UNIX Tips: How to find broken symbolic links
Recent Comments
- Alisa M. on FreeBSD: How To Upgrade FreeBSD 7 to 8 Stable Release
- Tiffany P on FreeBSD: How to Install Adobe Flash in FreeBSD 8
- angrypotato1 on How To Reset Keyring Password in Ubuntu
- Nick on Ubuntu: How to build and install Linksys AE1000 Wireless-N linux driver on Ubuntu 11.10
- Martin on FreeBSD: How to set up an UPnP Internet Gateway Device (IGD) with MiniUPnP and FreeBSD 9.0
Blogs
Links
Archives
- March 2012 (1)
- February 2012 (1)
- January 2012 (1)
- December 2011 (1)
- November 2011 (4)
- October 2011 (1)
- September 2011 (1)
- August 2011 (1)
- July 2011 (3)
- June 2011 (1)
- May 2011 (1)
- December 2010 (1)
- November 2010 (1)
- October 2010 (4)
- September 2010 (4)
- August 2010 (5)
- July 2010 (3)
- June 2010 (9)
- May 2010 (13)
- April 2010 (23)
- March 2010 (18)
- February 2010 (6)