Security Basics mailing list archives

RE: SSH Passphrase


From: Michael Cunningham <crayola () optonline net>
Date: Wed, 05 Mar 2003 19:49:06 -0500

I have accomplished this by generating a dsa key without a passphrase.
Although this works I am worried about the security concerns of doing
this? (Without a passphrase, how does it authenticate? Based on the
machines dsa key which was made from machine specific entropy?)

It doesn't really authenticate. If you have access to that account on
the 
server you are scping from, then you can login into the other box 
as well as that account. If you need a non interactive file transfer or 
login, then you are going to have to make some security concessions. 

I would suggest this.. http://www.sublimation.org/scponly/
It should help a little bit. 

And scp is definitely a lot better then rcp.. 

Mike
--
Michael J. Cunningham (CISSP, SCNA, SCSA, CCSA)


Current thread: