delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2003/10/16/17:50:30

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
X-Injected-Via-Gmane: http://gmane.org/
To: cygwin AT cygwin DOT com
From: Andrew DeFaria <ADeFaria AT Salira DOT com>
Subject: Re: Passwordless login with ssh
Date: Thu, 16 Oct 2003 14:52:05 -0700
Lines: 37
Message-ID: <bmn3on$79j$2@sea.gmane.org>
References: <bmkmdl$82i$1 AT sea DOT gmane DOT org> <20031016081208 DOT GB28997 AT cygbert DOT vinschen DOT de> <bmmbha$43f$1 AT sea DOT gmane DOT org> <Pine DOT GSO DOT 4 DOT 56 DOT 0310161102500 DOT 20462 AT slinky DOT cs DOT nyu DOT edu>
Mime-Version: 1.0
X-Complaints-To: usenet AT sea DOT gmane DOT org
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
X-Accept-Language: en-us, en
In-Reply-To: <Pine.GSO.4.56.0310161102500.20462@slinky.cs.nyu.edu>

Igor Pechtchanski wrote:

>ssh -v (or -vvv) should tell you why the authorized_keys aren't accepted.
>It's possible the permissions are too lax on them.
>
This is ending up being the culprit. You see my home directory is on an 
SMB share. Now I had set CYGWIN to "ntsec smbntsec" in the Windows 
System Environment Variables so that services would see it and I thought 
that that would propogate down to the shells. But alas our /etc/profile 
explicitedly set CYGWIN to just "ntsec". With this setting my bash shell 
could chmod 600 <file> all it wanted to but if <file> was on an SMB 
share it would not change the mod bits! Changing /etc/profile to set 
CYGWIN to "ntsec smbntsec" now allows me to chmod on SMB shares. After 
setting the permissions correclty on the files in ~/.ssh ssh'ing works!

Now on to another problem. Perhaps this can't be done. As the user 
adefaria I wish to ssh to another machine as another user (ccadmin) and 
not be prompted with a password. Is this doable without "giving away the 
farm" security-wise? To allow certain users the right to ssh as another 
user without the need for a password?

Finally, I would like to ssh to my home machine without needing a 
password. At work I'm adefaria, at home I'm Andrew. I wish to

$ hostname
adefaria
$ echo $USER
adefaria
$ ssh Andrew@<home>.com

and have my home machine set up to allow adefaria AT adefaria to come in as 
Andrew.
-- 
When something is "new and improved!". Which is it? If it's new, then 
there has never been anything before it. If it's an improvement, then 
there must have been something before it.



--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019