Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: public key (RSA) authentication problem

From: Turner, Carl H [NTWK SVCS] <CarlTurner(at)NMCC.SprintSpectrum.com>
Date: Thu Aug 14 2003 - 13:53:16 EDT


I wouldn't suggest setting ~/.ssh and ~/.ssh/authorized_keys to 755. Try 755 on the ~/.ssh and 600 for ~/.ssh/* I believe the users home dir (~/) must also be 755.

openssh will not allow the key transfer to take place if the permissions above are not set. If you are still not getting a public key to work, try starting the client in debug mode (-vvv) or the sshd (-ddd) and reply with the contents. It will tell you exactly why the transfer is being denied.

-Carl

-----Original Message-----
From: Schubert, John [NTWK SVCS]
Sent: Wednesday, August 13, 2003 1:15 PM To: Ben Green
Cc: secureshell@securityfocus.com
Subject: RE: public key (RSA) authentication problem

Anytime I've had problems logging in with swapped public keys, the following ownership changes have fixed it 99% of the time: (entered from the user's home directory. e.g. cd /home/username )

chmod 755 . .ssh .ssh/authorized_keys

Give that a try.

John

Do you need help?X

-----Original Message-----
From: Greg Wooledge [mailto:wooledg@eeg.ccf.org] Sent: Wednesday, August 13, 2003 10:47 AM To: Ben Green
Cc: secureshell@securityfocus.com
Subject: Re: public key (RSA) authentication problem

On Tue, Aug 12, 2003 at 09:12:17PM -0400, Ben Green wrote:
> As root, I can setup public key authentication and scp/sftp/ssh between two
> servers without a password. However, the same setup does not work as an
> ordinary user. I have checked permissions on everything in /etc/ssh and
> everything is world readable. I have checked the permissions on the private
> key file and it is 600. The permissions on the public key file is 644.

Check the directory permissions, too -- on every directory leading up to, and including, the .ssh directory. If any of them is either groupor  world-writable, then it will not work. Received on Thu Aug 14 15:37:57 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:02 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library