/srv/irclogs.ubuntu.com/2006/04/03/#ubuntu-server.txt

=== mgalvin [n=mgalvin@ubuntu/member/mgalvin] has joined #ubuntu-server
=== ubijtsa2 [n=anders@213.208.70.150] has joined #ubuntu-server
=== zenrox [n=zenrox@71.115.198.118] has joined #ubuntu-server
=== yves [n=yves@unaffiliated/nictuku] has joined #ubuntu-server
=== mgalvin [n=mgalvin@ubuntu/member/mgalvin] has joined #ubuntu-server
=== yves [n=yves@unaffiliated/nictuku] has joined #ubuntu-server
=== pab1 [n=peter@c-68-61-247-219.hsd1.mi.comcast.net] has joined #ubuntu-server
pab1can some one here help explain a couple things about ssh05:45
pab1?05:46
infinity?05:46
pab1Well im having trouble grasping onto where exactly I should be storing my pub and priv keys05:46
infinityprivate keys go in .ssh on the machine you generated them on (which is going to be the "client" machine)05:47
pab1ok that helps a lot05:47
infinitypublic keys get copied into .ssh/autorized_keys on the target ("server") machine.05:47
pab1in the home directory?   ~/.ssh/authorized_keys ?05:48
infinityYes, ~/.ssh/authorized_keys is just a text file, with one public key per line.05:48
infinity(Well, it's more complext than that, you can limit what commands can be run by that key, etc, but by default, it's just "one key per line to allow access")05:48
pab1ok cool05:49
pab1so i just create the auth_key path in any accounts home directory on the server?05:49
pab1then copy my pub key in auth_keys05:50
pab1and im good?05:50
infinityIt's a text file, not a directory. :)05:50
infinityBut otherwise, yeah.05:50
pab1o ok05:50
infinity(And make sure the permissions are right on the directory...)05:50
infinity~/.ssh must be owned by the user, and must be 070005:50
pab1MUST be 700?  or is that best practice?05:51
infinityMUST.05:51
pab1:o05:51
infinitysshd will tell you where to go and how to get there if it isn't.05:51
pab1haha05:51
infinity(And won't let you log in)05:51
pab1ok one more thing... if I put multiple pub keys in the auth_key FILE ( :) ) then each of those clients can login as that user05:52
infinityYup.05:52
pab1if that is the case, how would I login from the client?  with the server account (ssh severacct@host)  or with client account (ssh clientacct@host)05:53
infinityserveracct.05:54
pab1ok05:54
pab1thanks a lot man, uve been a huge help!05:54
infinityWhen you do "ssh foo@host", it authenticates on the remote end as "foo".05:54
infinityWhat user you are locally is irrelevant.05:54
pab1got it05:54
infinityNo different from "ftp user@host" or "http://user:pass@host/" :)05:54
pab1ya i see now, just the fact that the client will have a different priv key confused me a bit05:55
infinityThe name on the key (for instance, mine say "adconrad@cthulhu") is just a comment so you can have a vague idea of where it came from.  it's meaningless to sshd.05:56
infinityIt's only the long hex string that matters.05:56
infinityOr, ASCII, in the case of DSA and RSA keys for SSH2.05:56
infinityBut, yeah.  That long string (and the tag before it that says what sort of key it is, ssh-dss, etc) is what's important.05:57
pab1gotcha05:57
infinitysshd completely ignores the "user@host" comment on the end of the pub key, it's just a helpful comment for you to remember that you generated that key on host "foo" with user "bar". :)05:57
pab1so I could tecnically edit that last comment with no real change to the keys function?05:58
infinityAlso handy if you're setting up a semi-insecure shared account, and dave@domain.com send you an urgent (signed with GPG, I hope) email saying that he needs his public key changed... You'll know which one to delete. :)05:59
pab1not that I really have a reason05:59
infinityEditing the comment to be more informative can be done, yes.05:59
pab1haha06:00
pab1welp i'm gonna try all this out06:00
pab1thanks again!06:00
infinityHave fun.06:00
infinityDon't forget to save the backscroll until you're sure how it all works.06:01
infinityNo one likes people asking the same questions twice. ;)06:01
pab1im logging this :D06:01
pab1very helpful06:01
pab1are you a unix admin?  if you don't mind me asking06:03
infinityBy trade?.. Probably... I currently work on Ubuntu fulltime, though.06:04
pab1awesome06:05
pab1i like your OS :-P06:05
infinityThanks.  I'm rather fond of it too. :)06:05
pab1or distro i should say06:05
pab1let me pick your brain on this...  is there a way to use samba as a central login for win and linux?   Linux mainly being the one that I'm not sure on06:09
yvesuse06:12
yvespab1, a very nice, but not really simple, way is to use samba+ldap06:12
pab1hmm.  is there a straight forward way to do it or is that really the only route?06:13
yvesyou can use smbpasswd as your auth backend06:14
pab1i prolly should learn ldap anyways06:14
pab1maybe ill just do that06:14
pab1i use smbpasswd currently06:14
pab1just for file and print sharing tho06:15
yvesyou'd better first setup a domain using smbpasswd, then move on to ldap06:15
yvesthen it's just a matter of setting your samba server as a login server06:15
yvesone line change :-D06:15
pab1hmmm06:15
yvesthat would'nt work for linux local accounts, though06:15
yvesonly windows logons and file sharing auth06:15
pab1ya thats the thing06:16
pab1I actually did that before then run into the no linux login thing and the no admin group thing06:16
pab1ldap will allow for at least an admin group right?06:16
yvesyes, it will solve both problems06:17
pab1bah06:17
yvesits learning curve is high, i think06:17
pab1im gonna have to wait till after finals i think06:17
=== fabbione [i=fabbione@gordian.fabbione.net] has joined #ubuntu-server
=== fabbione [i=fabbione@gordian.fabbione.net] has joined #ubuntu-server
=== pab1 [n=peter@c-68-61-247-219.hsd1.mi.comcast.net] has left #ubuntu-server []
=== thefish [n=thefish@unaffiliated/thefish] has joined #ubuntu-server
=== maswan [i=maswan@kennedy.acc.umu.se] has joined #ubuntu-server
=== lbm [n=lbm@x1-6-00-13-10-7a-d1-e4.k233.webspeed.dk] has joined #ubuntu-server
=== zenrox [n=zenrox@71.115.198.118] has joined #ubuntu-server
=== Pygi [n=mario@83-131-242-196.adsl.net.t-com.hr] has joined #ubuntu-server
=== Pygi [n=mario@83-131-250-82.adsl.net.t-com.hr] has joined #ubuntu-server
=== zenrox [n=zenrox@71.115.198.118] has joined #ubuntu-server
=== mgalvin [n=mgalvin@ubuntu/member/mgalvin] has joined #ubuntu-server
=== lionelp [n=lionel@ip-128.net-82-216-65.rev.numericable.fr] has joined #ubuntu-server
=== zenrox [n=zenrox@71.115.198.118] has joined #ubuntu-server
=== lionelp [n=lionel@ip-128.net-82-216-65.rev.numericable.fr] has joined #ubuntu-server
=== evilmonkey [n=evilmonk@host-84-9-144-77.bulldogdsl.com] has joined #ubuntu-server
evilmonkeyhi06:14
Pygihi evilmonkey06:16
evilmonkeyis this the place to ask question about installing java sun sdk06:16
Pygidapper, breezy? you want java sdk on server??06:17
evilmonkeybrezzy, no, local for development with eclipse06:18
Pygi#ubuntu06:20
evilmonkeyok06:20
evilmonkeythankyou06:20
Pygiyw06:20
=== Jeeves_ [i=mark@net.prevented.net] has joined #ubuntu-server
Jeeves_Hi there07:40
=== ubijtsa2 [n=anders@213.208.70.150] has joined #ubuntu-server
=== hunger [n=tobias@p54A608EA.dip0.t-ipconnect.de] has joined #ubuntu-server
=== Pazzo [n=thomas@host130-250.pool8172.interbusiness.it] has joined #ubuntu-server
=== Pygi [n=mario@83-131-238-224.adsl.net.t-com.hr] has joined #ubuntu-server

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!