LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Lost device with SSH keys (https://www.linuxquestions.org/questions/linux-security-4/lost-device-with-ssh-keys-908485/)

ziphem 10-16-2011 04:31 PM

Lost device with SSH keys
 
If, somewhere in a large city, you lose your device that contains your SSH key to your PC, and to log in remotely to your PC you need those keys plus passphrase (no automatic log-in is set up on the device), is it recommended to change keys? I think it's probably better to err on the side of caution, but it's a pain in the butt.

As a corralary, is it worth changing the passphrase when I generate the new key, or can I use again the old passphrase? It's worth noting I did not have the passphrase written anywhere, so that's not lost.

Thanks a ton!

lithos 10-16-2011 04:38 PM

delete the 'old' key on the server and create a new with some 1024 bit encryption (could be withous passw, but I make it with pass)

ziphem 10-16-2011 05:34 PM

I like to use passphrase. Do you think it's ok to use the same passphrase as I had before, or should I change it? Does it affect the security of the key?

Thanks.

Tinkster 10-16-2011 05:56 PM

Moved: This thread is more suitable in <Security> and has been moved accordingly to help your thread/question get the exposure it deserves.

unixfool 10-16-2011 08:40 PM

Quote:

Originally Posted by ziphem (Post 4500082)
I like to use passphrase. Do you think it's ok to use the same passphrase as I had before, or should I change it? Does it affect the security of the key?

Thanks.

Shouldn't matter what you do. If you use the old passphrase, it'll be with the new key (half of the two factor authentication will still be new...remember, even if someone knows your passphrase, they'd still have to have the key to gain access).


All times are GMT -5. The time now is 12:42 AM.