Setting Up Key Authentication
Goal
You create an SSH key, set its permissions, register it in authorized_keys, and actually connect. And you confirm that a key with a command= restriction really runs only that command.
Why it matters
Most public key authentication failures are a file permission problem, not cryptography. If ~/.ssh is group-writable, sshd silently rejects the key and asks for a password — because another user could put their own key in authorized_keys. That is, permissions are the authentication policy. And the command= restriction is effectively essential in deployment automation. Even if a CI server's key leaks, you can make it so that key can run only one specified command.
In this lab environment, a real sshd is running on 127.0.0.1:2222. It is in the same Pod, but from SSH's point of view it is a complete second server.
Steps
- Create an ed25519 key pair at
/root/.ssh/id_labhubwith no passphrase. - Set the permissions to 700 for
/root/.ssh, 600 for/root/.ssh/id_labhub, and 644 for/root/.ssh/id_labhub.pub. - Add the public key you just made to
/root/.ssh/authorized_keys. The file permissions must be 600. - With
ssh-keyscan, fetch the host key of127.0.0.1on port 2222 and register it in/root/.ssh/known_hosts. - Connect to
root@127.0.0.1:2222with that key, runhostnameremotely, and save the result to/root/ssh/connect.txt. - Create a
Host lab2block in/root/.ssh/config. It must contain five lines:HostName 127.0.0.1,Port 2222,User root,IdentityFile /root/.ssh/id_labhub, andIdentitiesOnly yes. Then confirm thatssh lab2 hostnamesucceeds and save it to/root/ssh/alias.txt. - Create a second ed25519 key at
/root/.ssh/id_restricted, and add its public key toauthorized_keys, putting the optionrestrict,command="/bin/hostname"at the very start of the line. When you runssh -i /root/.ssh/id_restricted -p 2222 root@127.0.0.1 idwith that key, the result ofhostnamemust come out, notid. Save that output to/root/ssh/restricted.txt. - Create
/root/ssh/keys.txt. It must hold the list of fingerprints of all the keys registered inauthorized_keys, and it must be at least 2 lines.
Notes
ssh-keygen -t ed25519 -N '' -f <경로>creates a key with no passphrase (the placeholder is the path).- You register the host key in the form
ssh-keyscan -p 2222 127.0.0.1 >> /root/.ssh/known_hosts. - With
ssh-keygen -lf /root/.ssh/authorized_keysyou can see the fingerprints of all the keys in the file. - Common mistake 1: overwriting with
>in step 3 so the existing keys disappear. Be sure to use>>. - Common mistake 2: putting a comma between the options and the key in step 7. Between the option list and the key type is a space.
Creating a key pair
Create an ed25519 key pair at /root/.ssh/id_labhub with no passphrase.
With ssh-keygen, -t specifies the type, -f the output path, and -N the passphrase. Leave the passphrase empty for automatic grading.
Setting permissions
Set the permissions to 700 for /root/.ssh, 600 for /root/.ssh/id_labhub, and 644 for /root/.ssh/id_labhub.pub.
The recommended permissions differ for directories and files. Only the public key is fine for others to read.
Registering the public key
Add the public key you just made to /root/.ssh/authorized_keys. The file permissions must be 600.
authorized_keys is a text file that holds one public key per line. Do not delete the existing lines; append.
Registering the host key
With ssh-keyscan, fetch the host key of 127.0.0.1 on port 2222 and register it in /root/.ssh/known_hosts.
ssh-keyscan has an option to specify the port, and a non-standard port goes into known_hosts in square-bracket notation.
Connecting with the key
Connect to root@127.0.0.1:2222 with that key, run hostname remotely, and save the result to /root/ssh/connect.txt.
Specify the key with -i and the port with -p. If you attach the command to run remotely as an argument, it runs right after connecting.
Making an alias with client configuration
Create a Host lab2 block in /root/.ssh/config. It must contain five lines: HostName 127.0.0.1, Port 2222, User root, IdentityFile /root/.ssh/id_labhub, and IdentitiesOnly yes. Then confirm that ssh lab2 hostname succeeds and save it to /root/ssh/alias.txt.
Put HostName, Port, User, IdentityFile, and IdentitiesOnly inside the Host block. Then you connect with just the alias and no options.
Making a command-restricted key
Create a second ed25519 key at /root/.ssh/id_restricted, and add its public key to authorized_keys, putting the option restrict,command="/bin/hostname" at the very start of the line. When you run ssh -i /root/.ssh/id_restricted -p 2222 root@127.0.0.1 id with that key, the result of hostname must come out, not id. Save that output to /root/ssh/restricted.txt.
List the options, separated by commas, at the very start of the authorized_keys line. Turn everything off with restrict and allow only one thing with command.
Auditing the registered keys
Create /root/ssh/keys.txt. It must hold the list of fingerprints of all the keys registered in authorized_keys, and it must be at least 2 lines.
ssh-keygen has an option that lists the key fingerprints in a file. The comments come out along with them.