Secure Shell connection

Secure Shell (ssh) is a protocol that uses encryption to secure the connection between a client and a server. It is the standard way of communicating to any data center.

Openssh is the most widely known open source implementation of the ssh protocol, and this is what we will be using for this tutorial. You will not need to install anything since it is already installed by default on many Linux systems.

What will you learn ?

  • Establish secure connection between your computer and a server

The importance of key-pairs

ssh uses public-key cryptography, with the idea that a mathematical function can encode information in the form of random words through passwords. The passwords used to authentificate are called encryption key-pair: there is a public one (used to prove ownership) and a private one (to encrypt data). Just the owner of the private key can decode this information, otherwise it would require a hugh amount of compute power to decode it (finding big prime factors).

Note

No, ssh will not be dead because of quantum computing. There is a lot of research going on post-quantum cryptography.

Many application derives from this algorithm :

  • Connect to your mail acount
  • Pay via your credit card
  • Paying games online
  • Blockchain technology (mostly hashing algos)

Hand’s on

Create encription keys

  1. Open a prompt with ctrl+alt+t

  2. Create your keys

    ssh-keygen -t rsa
    
  3. Press enter at each step

  4. Your private key ~/.ssh/id_rsa and public key ~/.ssh/id_rsa.pub are now on your cmputer, you can open them to see how they look like.

    cat ~/.ssh/id_rsa.pub
    cat ~/.ssh/id_rsa
    

    It should look like:

    1
    2
    3
    4
    5
    6
    7
    8
    9
    -----BEGIN PUBLIC KEY-----
    MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiOOHnV8A4i5LNgVvgttw
    TWsqpMMUlSgMA0IIZqn1NPr6MeVGqyaYYp5Gt6z99hrFWFCpLWtGiGfJksTEcBbJ
    Km6ZdZkSgGOErQz3U7Q1Beltsrx4Xy+iTt1yy8J0s00usoEBl4e2gMV5Qo6jCvHH
    +NHAOBt+BvRuEhdpjHAU7mdwZmq3BOSSi3GFXwcTXVuPQmj52Zc0oXogz8LpMuGN
    S7Uy4CWiq5R1eqxSk8MzHqEc6erhFVBfV8QbOsk1COi9Iicaeo23xEsf3Skf6mdy
    u8XT/kbOZys26hxfa5M+zexp+sjMnGDWv7/LWrfhLQKuW4aG9SyU2lxHkPEON53g
    DQIDAQAB
    -----END PUBLIC KEY-----
    
     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    -----BEGIN RSA PRIVATE KEY-----
    MIIEpAIBAAKCAQEAiOOHnV8A4i5LNgVvgttwTWsqpMMUlSgMA0IIZqn1NPr6MeVG
    qyaYYp5Gt6z99hrFWFCpLWtGiGfJksTEcBbJKm6ZdZkSgGOErQz3U7Q1Beltsrx4
    Xy+iTt1yy8J0s00usoEBl4e2gMV5Qo6jCvHH+NHAOBt+BvRuEhdpjHAU7mdwZmq3
    BOSSi3GFXwcTXVuPQmj52Zc0oXogz8LpMuGNS7Uy4CWiq5R1eqxSk8MzHqEc6erh
    FVBfV8QbOsk1COi9Iicaeo23xEsf3Skf6mdyu8XT/kbOZys26hxfa5M+zexp+sjM
    nGDWv7/LWrfhLQKuW4aG9SyU2lxHkPEON53gDQIDAQABAoIBAE3i8CG5kX4gCwk0
    tIsHInHaXQwcN1Ta0WL1KmSHpY48kyjapIfzUNcj6WbO1j02ZDzowCmolRw9uXJ5
    5K9GN7Wd8lD4BI/qj+4Kp5sHuPehJpqBJBg8uSQYWh3XiaEPdFd6kZZPUKcaNPGK
    yPgMM9S+O5lxAxcf8pT2n0aZ6z7t3hM3Z/7VsLbpye7hDJVSW7PDlNcFwgj3SSp7
    DLH4Z+jdBSNDTg/78YdaWYICpVmxIAepeujyDpn3YRsukiFcsUxUS9HNBa3O2sR5
    oINFjOjNytCC0ZlNTCC+xoPARs4zVdT9+VVLM07QjRHUT2dnup7fMwDm8IFuV76N
    4wIw/F0CgYEA8WArvxGf2NyDP9n3Rqm6344P7Eo2ioDEXji8ctm3sIRAz3Kxh16x
    zvv3u5UNynwFYbAqaMY18gAbj2x+SkJtWJkt5y9xON6JH9ZVsPEoNMBmpg3JIinp
    ahnHthO/eWpzrcT8gywMDgGnoR/SpZ4VhIPs0dKUSY4QLncEMsOPaZsCgYEAkS66
    MTnMPFGigdjvZiw80tcZGT2bmkxdPPOi+B9yQDwcN6cJXqIXKpaK5djmf/7XHjmA
    TZAQGRPe3uZGfKEE8PUo2DC1Xml+B5xNILeBKVQkYX0kijiOFZJoClpa51kQGBmR
    uUJGbnpApL7ZxdrSQ9nFZi78tcMyxxNPQrFwa3cCgYEAi7oyWM8pC27Lg8D3xi4n
    AZbJXO2xGQhlpG2PmaSzEzncErrATi7hG4L869fjPd4Bd4V1Z2WmgMrTKXmSugYu
    KmWyDuyFzHf2RTncLSvNLIxcX7AHSQGeH0+BLsPLyct335Xy3zQ2Xj1S/pDfbgRP
    TIDaLLSMJvBYKa23/nL6qBUCgYAEzO29KPMW34AnGPw5fab5NcGPsxjNDk9a75do
    6ulFNHeeY3iM14E6mEW5eeWNP+jvB+m1JtlRavXImwajolNegEy8cUfd+lD/gWyP
    c2Hi8vRNAO1PYLVaA0BLb1doJOrCUT4fSRC5IHO4vtLGlwiy06WSTmVuwSiRqpLJ
    WsKj2wKBgQC7faYawFuSTehpeUcZfL5P5+9lV79tm9SwTakayYE8ESxNmuXqx24C
    9wouvhlmUia3reigiMU6B/HmL5nMR4Ep1FjAKHqyf0LlwBFA4wSOhfVZOehKtD/e
    ic9keF5Mg9/SJZsUUXDH0by9cmgbakSRPOWyV/Q74xQX79zHbbKTKA==
    -----END RSA PRIVATE KEY-----
    

Warning

You should NEVER share your private key id_rsa to anyone, nor leaving it on a remote server. As mentionned before, the private key allows to decode the informations you are sending. Avoid sharing the public key id_rsa.pub if unnecessary, hackers could use it to identify you.

Connect to a server

  1. We will try to connect to elm,

    ssh <you_username>@elm
    

    Note

    When using ssh, it will automatically detect your key under ~/.ssh. You can specify a key with -i /path/to/my/key.

  2. You can now type your UNF password.

  3. On your computer, you will see a new file ~/.ssh/known_hosts. It contains all the servers that you connected to.

Note

You can also connect to a server via its public IP in the form XXX.XX.XX.XX

A few tips

Automatic authentification

Every time you login to a server, you will be asked for the password if available. To avoid that, you can add your public key so the server doesn’t need your password to prove ownership.

  1. Send your public key to the server,

    ssh-copy-id <you_username>@elm
    
  2. After log-in to the server, you will be asked for your password a last time. Whenever you log-in again, it should not ask for it.

    ssh <your_username>@elm
    
  3. You can check the file ~/.ssh/authorized_keys on the server, it should match your public key id_rsa.pub.

Easy ssh

It can be cumbersome to type the ssh command if you have lot of arguments. For example, let’s say you want to set-up port forwarding on a specific server with a specific user, you would need to type:

ssh -L 1234:localhost:80 -i ~/.ssh/root/id_root root@server2.domain.cloud.com

It is possible to put all the options inside a single file in ~/.ssh/config, and call ssh with a single command. For example, you would call the previous command with just:

ssh server1

With this ~/.ssh/config:

1
2
3
4
5
6
7
8
9
Host server1
	HostName server2.domain.cloud.com
    User root
    IdentityFile ~/.ssh/root/id_root
    LocalForward 1234 localhost:80

Host server2
	HostName 200.00.00.00
	User ubuntu

Enabling display

Though it is not recomended because of performance, you can log in while enabling display by using the x11 forwarding option ssh -X. This can be usefull if you are running MATLAB for example and need the graphical interface.

Note

The server maybe doesn’t allow display, this can be checked from X11Forwarding option in /etc/ssh/sshd_config (if you are root).

Questions ?

If you have any issues with ssh, you can ask on the SIMEXP lab slack in #neuroinformatics channel!