Difference between revisions of "Passwordless SSH"
Jump to navigation
Jump to search
(→ESXi1) |
|||
Line 12: | Line 12: | ||
*<code>ls -l</code> | *<code>ls -l</code> | ||
*<code>cp /.ssh/* /vmfs/volumes/Admin/Utilities/ssl/ESXi1/keys</code> | *<code>cp /.ssh/* /vmfs/volumes/Admin/Utilities/ssl/ESXi1/keys</code> | ||
+ | |||
+ | *<code>vi /etc/ssh/sshd_config</code> | ||
+ | |||
+ | PermitRootLogin yes | ||
+ | UsePAM yes | ||
+ | # only use PAM challenge-response (keyboard-interactive) | ||
+ | PasswordAuthentication no | ||
+ | # ?????? # | ||
+ | ChallengeResponseAuthentication no | ||
+ | |||
+ | *<code>/etc/init.d/SSH restart</code> | ||
<br /> | <br /> | ||
Line 37: | Line 48: | ||
ChallengeResponseAuthentication no | ChallengeResponseAuthentication no | ||
− | * <code>/etc/init.d/SSH restart</code> | + | *<code>/etc/init.d/SSH restart</code> |
Revision as of 22:27, 6 July 2020
ESXi0
mkdir /vmfs/volumes/Admin/Utilities/ssl
mkdir /vmfs/volumes/Admin/Utilities/ssl/ESXi1
mkdir /vmfs/volumes/Admin/Utilities/ssl/ESXi1/keys
mkdir /.ssh
cd /.ssh
/usr/lib/vmware/openssh/bin/ssh-keygen -t rsa -b 4096
ls
cat id_rsa.pub | ssh root@ESXi1 'cat >> /etc/ssh/keys-root/authorized_keys'
cd /etc/ssh/keys-root/
ls -l
cp /.ssh/* /vmfs/volumes/Admin/Utilities/ssl/ESXi1/keys
vi /etc/ssh/sshd_config
PermitRootLogin yes UsePAM yes # only use PAM challenge-response (keyboard-interactive) PasswordAuthentication no # ?????? # ChallengeResponseAuthentication no
/etc/init.d/SSH restart
ESXi1
mkdir /vmfs/volumes/Admin/Utilities/ssl
mkdir /vmfs/volumes/Admin/Utilities/ssl/ESXi0
mkdir /vmfs/volumes/Admin/Utilities/ssl/ESXi0/keys
mkdir /.ssh
cd /.ssh
/usr/lib/vmware/openssh/bin/ssh-keygen -t rsa -b 4096
ls
cat id_rsa.pub | ssh root@ESXi0 'cat >> /etc/ssh/keys-root/authorized_keys'
cd /etc/ssh/keys-root/
ls -l
cp /.ssh/* /vmfs/volumes/Admin/Utilities/ssl/ESXi0/keys
vi /etc/ssh/sshd_config
PermitRootLogin yes UsePAM yes # only use PAM challenge-response (keyboard-interactive) PasswordAuthentication no # ?????? # ChallengeResponseAuthentication no
/etc/init.d/SSH restart