LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-20-2006, 10:14 AM   #1
tpe
Member
 
Registered: Oct 2004
Location: Athens, Greece
Distribution: Suse Linux
Posts: 98

Rep: Reputation: 16
SSH lock outs


Dear all,
I have the following problem: I use ssh and keychain in order to get the bakcups of my web site to my local pc. I do not have any problem with the procedure, but my ISP asked me to add a check before any scp action in order to ensure that the passphrase is entered correctly. keychain help is not very informative about the matter. Can someone help me?
 
Old 04-20-2006, 10:50 AM   #2
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,491

Rep: Reputation: 50
what sort of check?

are you using ssh-agent to pass the passphrase between machines?

what's the point of what they are asking?
 
Old 04-21-2006, 02:43 AM   #3
tpe
Member
 
Registered: Oct 2004
Location: Athens, Greece
Distribution: Suse Linux
Posts: 98

Original Poster
Rep: Reputation: 16
Quote:
Originally Posted by satinet
what sort of check?
I want to know if the passphrase is entered from the user. In the case of power fail, the script will try to scp the backup data either the user has loged in or not. I want to be sure that the passphrase is entered.

Quote:
Originally Posted by satinet
are you using ssh-agent to pass the passphrase between machines?
I use keychain

Quote:
Originally Posted by satinet
what's the point of what they are asking?
I have to download a lot of files. If the passphrase is not entered, then the web server will log a lot of unauthorized tries of scp. That is an abuse. Thus, before ANY scp I have to check that the passwordless login is working.

I tried to get the results of a simple command (eg date) using
Code:
scp user@host date > login.txt
but if the user had not entered the passphrase the file was empty. I found no way of retreive the "enter the passphrase" or any similar attempt.
 
Old 04-21-2006, 02:47 AM   #4
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,491

Rep: Reputation: 50
what's "keychain" anyway? I'm not sure what it does....

is it similar to ssh-agent?
 
Old 04-21-2006, 02:49 AM   #5
tpe
Member
 
Registered: Oct 2004
Location: Athens, Greece
Distribution: Suse Linux
Posts: 98

Original Poster
Rep: Reputation: 16
keychain is a wrapper of ssh-agent.
http://www.gentoo.org/proj/en/keychain/
 
Old 04-21-2006, 03:14 AM   #6
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,491

Rep: Reputation: 50
are you doing this using a script?

could you use the exit value to exit the script if the wrong pass phrase is entered.....

if you're using this key chain i dont know how the wrong pass phrase can get entered....

also which way is the copy happening...?
 
Old 04-21-2006, 04:06 AM   #7
tpe
Member
 
Registered: Oct 2004
Location: Athens, Greece
Distribution: Suse Linux
Posts: 98

Original Poster
Rep: Reputation: 16
That's exactly the problem. I have no exit codes. keychain works as wrapper...
 
Old 04-21-2006, 04:44 AM   #8
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,491

Rep: Reputation: 50
how can it go wrong though if the passwords are being stored in the keychain. I dont understand........
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fedora 3 Network Drop outs lowebb Linux - Wireless Networking 2 09-09-2005 09:07 AM
How to lock out ip's that try to ssh by force mazzo Linux - Security 3 08-19-2004 02:28 PM
ssh lock up on multi line output Incanus Linux - Networking 0 07-20-2004 08:47 PM
SSH lock users to the Home Directory jasonweb Linux - Security 2 04-11-2003 06:20 PM
exporting the sound outs,how? l_9_l Linux - General 1 04-19-2002 10:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration