Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Для включение защиты по PIN-коду  коду,  установите пакет ssh-askpass:
    Code Block
    languagebash
    $ sudo apt-get install ssh-askpass
  2. Для того, чтобы запрашивался PIN-код, укажите ssh-agent:
    Code Block
    languagebash
    $ eval "$(ssh-agent -s; SSH_ASKPASS=/usr/bin/ssh-askpass)"
  3. Для генерации ключей:
    Code Block
    languagebash
    $ ssh-keygen -t ecdsa-sk -O resident -O application=ssh:YourTextHere -O verify-required
    Generating public/private ecdsa-sk key pair.
    You may need to touch your authenticator to authorize key generation.
    Enter file in which to save the key (/home/tester/.ssh/id_ecdsa_sk): 
    /home/tester/.ssh/id_ecdsa_sk already exists.
    Overwrite (y/n)? y
    Enter passphrase (empty for no passphrase): 
    Enter same passphrase again: 
    Your identification has been saved in /home/tester/.ssh/id_ecdsa_sk
    Your public key has been saved in /home/tester/.ssh/id_ecdsa_sk.pub
    The key fingerprint is:
    SHA256:/vIIfHBajgeOHYoMjbzaE2eUoXU40jwSALfpuHjr9YA tester@tester2310
    The key's randomart image is:
    +-[ECDSA-SK 256]--+
    |+.o+ .           |
    | .ooO .          |
    |  o= *           |
    |.=. o            |
    |+.o.  + S        |
    |.+ooo* @         |
    |o.E+= B =        |
    |.o.o o +.o       |
    |..+.  . .oo      |
    +----[SHA256]-----+
  4. Скопируйте открытый ключ на сервер:
    Code Block
    languagebash
    $ ssh-copy-id -i /home/tester/.ssh/id_ecdsa_sk.pub tester@192.168.88.129
    /usr/bin/ssh-copy-id: INFO: Source of key(s) to be installed: "/home/tester/.ssh/id_ecdsa_sk.pub"
    /usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
    /usr/bin/ssh-copy-id: INFO: 1 key(s) remain to be installed -- if you are prompted now it is to install the new keys
    tester@192.168.88.129's password: 
    
    Number of key(s) added: 1
    
    Now try logging into the machine, with:   "ssh 'tester@192.168.88.129'"
    and check to make sure that only the key(s) you wanted were added.

Настройка Клиента 2 (Windows)

  1. Для использования Чтобы использовать Рутокен MFA для подключения в подсистеме WSL2 необходимо установить , установите пакет openssh betta. Для этого необходимо открыть командную строку CMD и выполнить команды:
    Code Block
    winget search "openssh beta"
    winget install "openssh beta"
  2. Запускаем Запустите оболочку WSL2 и добавляем добавьте переменную окружения для использования устройств FIDO2. Для этого в командной строке выполним команды:
    Code Block
    languagebash
    wsl
    $ export SSH_SK_HELPER="/mnt/c/Program Files/OpenSSH/ssh-sk-helper.exe"
  3. Далее необходимо скопировать Скопируйте файлы ключей для подключения по ssh в папку ~/.ssh/
    Code Block
    languagebash
    $ cp /mnt/c/id_ecdsa_sk ~/.ssh
    $ cp /mnt/c/id_ecdsa_sk.pub ~/.ssh

...