SearchTalks, papers and other documentsUser loginContent by categoryBlog postsTalks, papers and documents |
SSH visual host keysSubmitted by gwolf on Thu, 10/30/2008 - 18:14
Via Kees Cook (and sorry for the reiteration for people following along Planet Debian, thanks to Caspar Clemens: Recent (>= 5.1) versions of OpenSSH (found at least in Debian Lenny and Ubuntu Intrepid), have the VisualHostKey option. What does it do? $ ssh -o VisualHostKey=yes 172.16.10.1 Host key fingerprint is db:7a:d8:a8:2e:41:a2:e5:51:e1:7f:d0:73:bd:85:bf +--[ RSA 2048]----+ | .. | | .. . . . | | .. . o . o . | | + .. . o + | | + + . S . . | |. . . . o . | | . .+. E | | . o.o | | oo... | +-----------------+ Linux respaldos.local.iiec 2.6.26-1-vserver-amd64 #1 SMP Wed Oct 1 13:08:10 UTC 2008 x86_64 What does this mean? This ASCII-art graph represents your host's public key, which uniquely identifies (or at least, it better damn should uniquely identify!) it. This representation was added mainly because it is way easier to be able to visually record the shape of your most frequently used hosts' IDs than their fingerprint. If you connect from a foreign or untrusted machine (i.e. one that does not yet know your host's identity), make sure to run with this switch - it will protect you from somebody supplanting your server's identity. Host * VisualHostKey yes Now... What about publishing the list of the 32767 known-bad SSH keys? That'd make for a nice ASCII-art exhibit :-}
( categories: )
|
Random photoFortuneUpon the hearth the fire is red,
Beneath the roof there is a bed;
But not yet weary are our feet,
Still round the corner we may meet
A sudden tree or standing stone
That none have seen but we alone. Still round the corner there may wait
Tree and flower and leaf and grass, A new road or a secret gate,
Let them pass! Let them pass! And though we pass them by today
Hill and water under sky, Tomorrow we may come this way
Pass them by! Pass them by! And take the hidden paths that run
Towards the Moon or to the Sun,
Home is behind, the world ahead, Apple, thorn, and nut and sloe,
And there are many paths to tread Let them go! Let them go!
Through shadows to the edge of night, Sand and stone and pool and dell,
Until the stars are all alight. Fare you well! Fare you well!
Then world behind and home ahead,
We'll wander back to home and bed.
Mist and twilight, cloud and shade,
Away shall fade! Away shall fade!
Fire and lamp, and meat and bread,
And then to bed! And then to bed!
-- J. R. R. Tolkien
Live trafficCurrent weatherMexico City
Thu, 09/02/2010 - 04:46 |
Strictly speaking...
„If you connect from a foreign or untrusted machine...“ – if the machine you connect from is untrusted, then it does not add much theoretical security (as the ssh binary could be modified). Correct would be „if you connect from a trusted machine on an untrusted network to your server for the first time...“. But practically, of course you are right.
BTW, your ASCII captcha is broken here (no mono font, or no fallback in the font specification).
But where is the "@"?
But where is the "@"?
Not everything in life...
is a nethack game!
Post new comment