Pagina 1 di 1

Autenticazione RSA

Inviato: gio 25 mag 2006, 19:56
da Unicondor
Volevo effettuare sul mio server l'autenticazione rsa pero' quando ci provo ho sempre un problema..quando vado ad abilitare i comandi in sshd.conf ed apro putty, appena si apre la schermata nera si chiude automaticamente. Credo di aver seguito tutto bene dalla generazioen delle chiavi con puttygeneretor ed uso di pageant..fore il problema è nel mio sshd.conf o file affini ed esso (ssh.host.rsa ecc...)
ecco il mio sshd.conf

Port 22
#Protocol 2,1
#ListenAddress 0.0.0.0
#ListenAddress ::

# HostKey for protocol version 1
#HostKey /etc/ssh/ssh_host_key
# HostKeys for protocol version 2
#HostKey /etc/ssh/ssh_host_rsa_key
#HostKey /etc/ssh/ssh_host_dsa_key

# Lifetime and size of ephemeral version 1 server key
#KeyRegenerationInterval 1h
#ServerKeyBits 768

# Logging
#obsoletes QuietMode and FascistLogging
#SyslogFacility AUTH
#LogLevel INFO

# Authentication:

#LoginGraceTime 2m
PermitRootLogin no
#StrictModes yes
#MaxAuthTries 6

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
#RhostsRSAAuthentication no
# similar for protocol version 2
#HostbasedAuthentication no
# Change to yes if you don't trust ~/.ssh/known_hosts for
# RhostsRSAAuthentication and HostbasedAuthentication
#IgnoreUserKnownHosts no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes

# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication no
#PermitEmptyPasswords no

# Change to no to disable s/key passwords
#ChallengeResponseAuthentication no

# Kerberos options
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no

# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes

# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication mechanism.
# Depending on your PAM configuration, this may bypass the setting of
# PasswordAuthentication, PermitEmptyPasswords, and
# "PermitRootLogin without-password". If you just want the PAM account and
# session checks to run without PAM authentication, then enable this but set
# ChallengeResponseAuthentication=no
#UsePAM no

#AllowTcpForwarding yes
#GatewayPorts no
#X11Forwarding no
#X11DisplayOffset 10
#X11UseLocalhost yes
#PrintMotd yes
#PrintLastLog yes
#TCPKeepAlive yes
#UseLogin no
#UsePrivilegeSeparation yes
#PermitUserEnvironment no
#Compression yes
#ClientAliveInterval 0
#ClientAliveCountMax 3
#UseDNS yes
#PidFile /var/run/sshd.pid
#MaxStartups 10

# no default banner path
#Banner /some/path

# override default of no subsystems
Subsystem sftp /usr/libexec/sftp-server

qualcuno potrebbe dirmi il perche' del mio problema...Vi ringrazio in anticipo

Inviato: ven 26 mag 2006, 10:12
da sid77
premetto che non ho mai usato putty, ma:
1) prova a lanciarlo da cmd.exe, apri un prompt e ci scrivi dentro putty utente@indirizzo_ip magari ti spiega perchè non ha voglia di funzionare.
2) tanto per essere paranoico, cambia la riga: "#Protocol 2,1 " in "Protocol 2"

non ho capito troppo bene un passaggio, come hai generato la coppia di chiavi?

ciao

Inviato: ven 26 mag 2006, 11:37
da Unicondor
sid77 provero il prima possibile la tua soluzione..comunque le chiavi le ho create con puttygenerator (tpo delle chiavi RSA-2 poiche ho letto che il primo è bucato) e le ho copiate correttamente nella directory dell'user che ho creato appositamente per questa autenticazione...la directory è la seguente .ssh/authorized_keys: ti mostro output del file
---- BEGIN SSH2 PUBLIC KEY ----
Comment: "serverbn"
AAAAB3NzaC1kc3MAAACBAI9NaTX8cw0c72evnZMsvH7vmBzHLtz7LfyPoxvpq+3W
QZApErCKCVTMM9Ba4/LUeVPOly7zRizacXvLPwa9rqzqaHwwHiMEG6W0WU7rBRtv
4sO3z1bwVRajFtrLVrCmwId6s/3b83Cn3uI7VDvDBMm5lAsVfCuxcSuZO5CMQEgj
AAAAFQCX5YLpN3/5XnognAmehd+RH1IH7QAAAIA7XT75HJbXEmlXuRgYUvX7Amyr
RC6sjQCHT+6kCW3kv/FW5vafZmW+hEgSrLecZ7FnUJBv+QTynF+Mlm9Ki6sD6E+b
gefVmJZ5GSb80eaELaaO+Mfy9qomfdho+Fzy+cqn++BntuIguY7GohguZHGQ8KKj
***************************************************************************************
yQ==
---- END SSH2 PUBLIC KEY ----

Inviato: ven 26 mag 2006, 13:16
da sid77
come struttura, le mie chiavi sono parecchio diversa dalla tua.
un chiave dovrebbe essere fatta così:

ssh-$TIPO ...lettere...numeri...altrecose...== utente@hostname

io ho usato il comando "ssh-keygen"
ciao