Re: [kde-linux] Starting ssh at log-in



On 22.11.2006 21:48, Anne Wilson wrote:
My concern is not severe, since this is a family lan and I have no reason
to mistrust any family member. However, on principle, I like to have a
number of layers of security. Of course my user password is the first
obstacle. After that, there is the matter of running shell scripts that
copy data across to the server. For this my ssh passphrase is required. I
may be working actually away from the computer at the time that cron
requires the passphrase, so I use keychain to cache it.

I don't think that's exactly what I need. All I am concerned with is

a) I must be asked for the passphrase to enable the scripts to work
b) it should happen early enough to avoid the situation where I get busy in
the next room and forget to do it in time for the first call.

I suppose I'm close to being paranoid on this - if I'm not working at the
box there probably isn't much to transfer anyway. All the same, there's
not much point in using ssh unless I make it as secure as possible and
convenient as possible without losing that security.

Anne

Hi again,
There are two things that I would like to point out.

First, if you use password caching anyway, it is only the first time you are
prompted for the password. Then the alternative of typing just 'y' rather
that the hole password lacks only in the event of someone else starting YOUR
KDE session, which is already a security hole (Even in the family you don't
share linux users, do you? There is no reason to do so...:) ).

Second, even if you do type your password the first time, you said in some
previous post that your konsole flicks on the screen and then exits. This
could mean two things (at leas I can think of two right now)
a) Your password is retrieved from elsewhere (something like .netrc file
perhaps?) or a defferent authentication method is used.
b) Your backup script fails to prompt for the password and exits prematurely,
causing your konsole to exit too, because it is started with the backup
script to run rather than a shell.

You can determine what is happening by running your script manually, trying to
run konsole automatically with some other command to execute for testing,
monitoring on the remote server if the backup is successful, etc.

By the way, my console gets messy in the way you described (transparency, keys
not responding etc.) when I try to run a konsole set up with transparent
background with X forwarding.

I think you have pretty much options on how to do what you want, you simply
need to pick up one! And, yes, I know this could be the hardest part:) So
good luck again...

--
Blade hails you...

My fall will be for you
My love will be in you
If you be the one to cut me
I'll bleed forever
--Nightwish

Attachment: pgphWPXtF4IK2.pgp
Description: PGP signature

___________________________________________________
This message is from the kde-linux mailing list.
Account management: https://mail.kde.org/mailman/listinfo/kde-linux.
Archives: http://lists.kde.org/.
More info: http://www.kde.org/faq.html.

Relevant Pages

  • Enabling macros in ThisOutlookSession / putting them elsewhere
    ... I've created a script for use with a rule in Rules Wizard and have put it ... The first time that rule runs in each ... I get a security dialog. ... In my Security Panel, on the Trusted Publishers tab, the "Trust access to ...
    (microsoft.public.outlook.program_vba)
  • SUMMARY WAS: OT? Philosophical Question on SA responsibilities
    ... helpful for managers interested in hiring new administrators. ... Would you go thru the 14,600 messages in root and admin ... If I was a new SA I would if encountering a security hole, ... I can see some use for the passwd -s part of the crontab script, ...
    (SunManagers)
  • Re: Clarification-Win2k Netstat sockets interpretation
    ... snip.. ... Before I could manually download every security upate and servicepack from MS.com but now...they send you a bit of Cop-code that fails to run unless ALL defences are down ... Are you sure the script from ntsvcfg is benign in addition to being useful? ... You are absolutely correct there HAL, er ah, Sebastian. ...
    (alt.computer.security)
  • [NT] Flaw in Windows Script Engine Could Allow Code Execution
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Windows Script Engine provides Windows operating systems with the ... blocked by Outlook Express 6.0 and Outlook 2002 in their default ...
    (Securiteam)
  • Re: BUG with RES/SCRIPT/XP-SP2
    ... I consider JavaScript (known to security people as JavaVirus) as one of the Really Top ... to have a bad script cause damage to my machine. ... This security feature is called the "Local Machine Zone Lockdown". ... Tags, and the CDHtmlDialog class in this forum, and got no response. ...
    (microsoft.public.vc.mfc)