Security Basics mailing list archives

SSH Passphrase


From: Stefan Lesicnik <lists () lsd za com>
Date: 05 Mar 2003 23:06:47 +0200

Hi, 

Im fairly new to private and public key encryption, so dont quite
understand all the concepts.

I have the need to scp a file to a remote server without specifying the
password as it is done from a non-interactive script.

I have accomplished this by generating a dsa key without a passphrase.
Although this works I am worried about the security concerns of doing
this? (Without a passphrase, how does it authenticate? Based on the
machines dsa key which was made from machine specific entropy?)

I know of programs such as ssh-agent, but these require you to enter a
passphrase at the beginning of the session which it then remembers, this
isnt possible as it is non-interactive in my case. Does anyone have any
ideas or comments?

TIA
Stefan Lesicnik



Current thread: