Showing posts with label ssh. Show all posts
Showing posts with label ssh. Show all posts

Friday, 13 April 2012

Passwordless SSH Authentication

[root@station1 ~]# ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/root/.ssh/id_rsa):  (dont type anyting just press enter everywhere)
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /root/.ssh/id_rsa.
Your public key has been saved in /root/.ssh/id_rsa.pub.
The key fingerprint is:
d8:98:4b:01:c2:dc:95:be:17:c3:5a:23:02:dc:06:00 root@station1.example.com
The key's randomart image is:
+--[ RSA 2048]----+
|E=o+....         |
|  =.+..          |
|   o ...         |
|    . o**        |
|     .==S+       |
|     .o..        |
|      ..         |
|                 |
|                 |
+-----------------+
[root@station1 ~]#
[root@station1 ~]# scp -r /root/.ssh/id_rsa.pub 10.65.62.32:/root/.ssh/id_rsa.pub.server
[root@station1 ~]# ssh 10.65.62.32
Password:

[root@station2 ~]# cat /root/.ssh/id_rsa.pub.server >> /root/.ssh/authorized_keys
[root@station2 ~]# vim /etc/ssh/sshd_config

  49 AuthorizedKeysFile      .ssh/authorized_keys

[root@station2 ~]# service sshd restart
[root@station2 ~]# exit
[root@station1 ~]# ssh 10.65.62.32
now with out asking password it will login to station2
[root@station2 ~]#

Securing SSH

[root@station1 ~]# vim /etc/ssh/sshd_config

 41 LoginGraceTime 2m
 42 PermitRootLogin no
 43 StrictModes yes
 44 MaxAuthTries 3
 45 MaxSessions 3


Find ClientAliveInterval and set to 600 (10 minutes) as follows:

119 ClientAliveInterval 600   ----> client can interact with server for only 10min.
120 ClientAliveCountMax 0

[root@station1 ~]# service sshd restart
Stopping sshd:                                            [  OK  ]
Starting sshd:                                             [  OK  ]

Thursday, 12 April 2012

ssh welcome banner

[root@station1 ~]# ssh station2
root@station2 password:
Last login: Mon Apr 10 18:58:43 2012 from localhost.localdomain
[root@station2 ~]#
Changing this message requires editing two different files. Open /etc/motd file and enter banner message.
[root@station2 ~]# vim /etc/motd
welcome to station2
Save and exit the file.
Now open sshd configuration file /etc/ssh/sshd_config,
[root@station2 ~]# vim /etc/ssh/sshd_config
PrintLastLog no ----->find this line and edit
Save and exit the file. Restart SSH service,
[root@station2 ~]# service sshd restart
[root@station2 ~]# exit
Now when you login, we will get below message,
[root@station1 ~]# ssh station2
root@station2 password:
Last login: Mon Apr 10 18:58:43 2012 from localhost.localdomain
Welcome to station2      ---------> see your welcome message
[root@ station2 ~]#