TT Lab
Get started
Learn Learning paths Courses

SSH and File Transfer

Setting Up Key Authentication

Continue in TT Lab

Goal

You create an SSH key, set its permissions, register it in authorized_keys, and actually connect. And you confirm that a key with a command= restriction really runs only that command.

Why it matters

Most public key authentication failures are a file permission problem, not cryptography. If ~/.ssh is group-writable, sshd silently rejects the key and asks for a password — because another user could put their own key in authorized_keys. That is, permissions are the authentication policy. And the command= restriction is effectively essential in deployment automation. Even if a CI server's key leaks, you can make it so that key can run only one specified command.

In this lab environment, a real sshd is running on 127.0.0.1:2222. It is in the same Pod, but from SSH's point of view it is a complete second server.

Steps

  1. Create an ed25519 key pair at /root/.ssh/id_labhub with no passphrase.
  2. Set the permissions to 700 for /root/.ssh, 600 for /root/.ssh/id_labhub, and 644 for /root/.ssh/id_labhub.pub.
  3. Add the public key you just made to /root/.ssh/authorized_keys. The file permissions must be 600.
  4. With ssh-keyscan, fetch the host key of 127.0.0.1 on port 2222 and register it in /root/.ssh/known_hosts.
  5. Connect to root@127.0.0.1:2222 with that key, run hostname remotely, and save the result to /root/ssh/connect.txt.
  6. Create a Host lab2 block in /root/.ssh/config. It must contain five lines: HostName 127.0.0.1, Port 2222, User root, IdentityFile /root/.ssh/id_labhub, and IdentitiesOnly yes. Then confirm that ssh lab2 hostname succeeds and save it to /root/ssh/alias.txt.
  7. Create a second ed25519 key at /root/.ssh/id_restricted, and add its public key to authorized_keys, putting the option restrict,command="/bin/hostname" at the very start of the line. When you run ssh -i /root/.ssh/id_restricted -p 2222 root@127.0.0.1 id with that key, the result of hostname must come out, not id. Save that output to /root/ssh/restricted.txt.
  8. Create /root/ssh/keys.txt. It must hold the list of fingerprints of all the keys registered in authorized_keys, and it must be at least 2 lines.

Notes

Creating a key pair

Create an ed25519 key pair at /root/.ssh/id_labhub with no passphrase.

With ssh-keygen, -t specifies the type, -f the output path, and -N the passphrase. Leave the passphrase empty for automatic grading.

Setting permissions

Set the permissions to 700 for /root/.ssh, 600 for /root/.ssh/id_labhub, and 644 for /root/.ssh/id_labhub.pub.

The recommended permissions differ for directories and files. Only the public key is fine for others to read.

Registering the public key

Add the public key you just made to /root/.ssh/authorized_keys. The file permissions must be 600.

authorized_keys is a text file that holds one public key per line. Do not delete the existing lines; append.

Registering the host key

With ssh-keyscan, fetch the host key of 127.0.0.1 on port 2222 and register it in /root/.ssh/known_hosts.

ssh-keyscan has an option to specify the port, and a non-standard port goes into known_hosts in square-bracket notation.

Connecting with the key

Connect to root@127.0.0.1:2222 with that key, run hostname remotely, and save the result to /root/ssh/connect.txt.

Specify the key with -i and the port with -p. If you attach the command to run remotely as an argument, it runs right after connecting.

Making an alias with client configuration

Create a Host lab2 block in /root/.ssh/config. It must contain five lines: HostName 127.0.0.1, Port 2222, User root, IdentityFile /root/.ssh/id_labhub, and IdentitiesOnly yes. Then confirm that ssh lab2 hostname succeeds and save it to /root/ssh/alias.txt.

Put HostName, Port, User, IdentityFile, and IdentitiesOnly inside the Host block. Then you connect with just the alias and no options.

Making a command-restricted key

Create a second ed25519 key at /root/.ssh/id_restricted, and add its public key to authorized_keys, putting the option restrict,command="/bin/hostname" at the very start of the line. When you run ssh -i /root/.ssh/id_restricted -p 2222 root@127.0.0.1 id with that key, the result of hostname must come out, not id. Save that output to /root/ssh/restricted.txt.

List the options, separated by commas, at the very start of the authorized_keys line. Turn everything off with restrict and allow only one thing with command.

Auditing the registered keys

Create /root/ssh/keys.txt. It must hold the list of fingerprints of all the keys registered in authorized_keys, and it must be at least 2 lines.

ssh-keygen has an option that lists the key fingerprints in a file. The comments come out along with them.