Secure Shell connection¶
Secure Shell (ssh) is a protocol that uses encryption to secure the connection between a client and a server. It is the standard way of communicating to any data center.
Openssh is the most widely known open source implementation of the ssh protocol,
and this is what we will be using for this tutorial.
You will not need to install anything since it is already installed by default on many Linux systems.
Pre-requisites¶
- Our tutorial on An introduction of UNIX system and the command line
What will you learn ?¶
- Establish secure connection between your computer and a server
The importance of key-pairs¶
ssh uses public-key cryptography, with the idea that a mathematical
function can encode information in the form of random words through passwords. The passwords used to authentificate are called encryption key-pair:
there is a public one (used to prove ownership) and a private one (to encrypt data).
Just the owner of the private key can decode this information, otherwise it would require a hugh amount of compute power to decode it (finding big prime factors).
Note
No, ssh will not be dead because of quantum computing.
There is a lot of research going on post-quantum cryptography.
Many application derives from this algorithm :
- Connect to your mail acount
- Pay via your credit card
- Paying games online
- Blockchain technology (mostly hashing algos)
Hand’s on¶
Create encription keys¶
Open a prompt with
ctrl+alt+tCreate your keys
ssh-keygen -t rsa
Press enter at each step
Your private key ~/.ssh/id_rsa and public key ~/.ssh/id_rsa.pub are now on your cmputer, you can open them to see how they look like.
cat ~/.ssh/id_rsa.pub cat ~/.ssh/id_rsa
It should look like:
1 2 3 4 5 6 7 8 9
-----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAiOOHnV8A4i5LNgVvgttw TWsqpMMUlSgMA0IIZqn1NPr6MeVGqyaYYp5Gt6z99hrFWFCpLWtGiGfJksTEcBbJ Km6ZdZkSgGOErQz3U7Q1Beltsrx4Xy+iTt1yy8J0s00usoEBl4e2gMV5Qo6jCvHH +NHAOBt+BvRuEhdpjHAU7mdwZmq3BOSSi3GFXwcTXVuPQmj52Zc0oXogz8LpMuGN S7Uy4CWiq5R1eqxSk8MzHqEc6erhFVBfV8QbOsk1COi9Iicaeo23xEsf3Skf6mdy u8XT/kbOZys26hxfa5M+zexp+sjMnGDWv7/LWrfhLQKuW4aG9SyU2lxHkPEON53g DQIDAQAB -----END PUBLIC KEY-----
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27
-----BEGIN RSA PRIVATE KEY----- MIIEpAIBAAKCAQEAiOOHnV8A4i5LNgVvgttwTWsqpMMUlSgMA0IIZqn1NPr6MeVG qyaYYp5Gt6z99hrFWFCpLWtGiGfJksTEcBbJKm6ZdZkSgGOErQz3U7Q1Beltsrx4 Xy+iTt1yy8J0s00usoEBl4e2gMV5Qo6jCvHH+NHAOBt+BvRuEhdpjHAU7mdwZmq3 BOSSi3GFXwcTXVuPQmj52Zc0oXogz8LpMuGNS7Uy4CWiq5R1eqxSk8MzHqEc6erh FVBfV8QbOsk1COi9Iicaeo23xEsf3Skf6mdyu8XT/kbOZys26hxfa5M+zexp+sjM nGDWv7/LWrfhLQKuW4aG9SyU2lxHkPEON53gDQIDAQABAoIBAE3i8CG5kX4gCwk0 tIsHInHaXQwcN1Ta0WL1KmSHpY48kyjapIfzUNcj6WbO1j02ZDzowCmolRw9uXJ5 5K9GN7Wd8lD4BI/qj+4Kp5sHuPehJpqBJBg8uSQYWh3XiaEPdFd6kZZPUKcaNPGK yPgMM9S+O5lxAxcf8pT2n0aZ6z7t3hM3Z/7VsLbpye7hDJVSW7PDlNcFwgj3SSp7 DLH4Z+jdBSNDTg/78YdaWYICpVmxIAepeujyDpn3YRsukiFcsUxUS9HNBa3O2sR5 oINFjOjNytCC0ZlNTCC+xoPARs4zVdT9+VVLM07QjRHUT2dnup7fMwDm8IFuV76N 4wIw/F0CgYEA8WArvxGf2NyDP9n3Rqm6344P7Eo2ioDEXji8ctm3sIRAz3Kxh16x zvv3u5UNynwFYbAqaMY18gAbj2x+SkJtWJkt5y9xON6JH9ZVsPEoNMBmpg3JIinp ahnHthO/eWpzrcT8gywMDgGnoR/SpZ4VhIPs0dKUSY4QLncEMsOPaZsCgYEAkS66 MTnMPFGigdjvZiw80tcZGT2bmkxdPPOi+B9yQDwcN6cJXqIXKpaK5djmf/7XHjmA TZAQGRPe3uZGfKEE8PUo2DC1Xml+B5xNILeBKVQkYX0kijiOFZJoClpa51kQGBmR uUJGbnpApL7ZxdrSQ9nFZi78tcMyxxNPQrFwa3cCgYEAi7oyWM8pC27Lg8D3xi4n AZbJXO2xGQhlpG2PmaSzEzncErrATi7hG4L869fjPd4Bd4V1Z2WmgMrTKXmSugYu KmWyDuyFzHf2RTncLSvNLIxcX7AHSQGeH0+BLsPLyct335Xy3zQ2Xj1S/pDfbgRP TIDaLLSMJvBYKa23/nL6qBUCgYAEzO29KPMW34AnGPw5fab5NcGPsxjNDk9a75do 6ulFNHeeY3iM14E6mEW5eeWNP+jvB+m1JtlRavXImwajolNegEy8cUfd+lD/gWyP c2Hi8vRNAO1PYLVaA0BLb1doJOrCUT4fSRC5IHO4vtLGlwiy06WSTmVuwSiRqpLJ WsKj2wKBgQC7faYawFuSTehpeUcZfL5P5+9lV79tm9SwTakayYE8ESxNmuXqx24C 9wouvhlmUia3reigiMU6B/HmL5nMR4Ep1FjAKHqyf0LlwBFA4wSOhfVZOehKtD/e ic9keF5Mg9/SJZsUUXDH0by9cmgbakSRPOWyV/Q74xQX79zHbbKTKA== -----END RSA PRIVATE KEY-----
Warning
You should NEVER share your private key id_rsa to anyone, nor leaving it on a remote server. As mentionned before, the private key allows to decode
the informations you are sending. Avoid sharing the public key id_rsa.pub if unnecessary, hackers could use it to identify you.
Connect to a server¶
We will try to connect to
elm,ssh <you_username>@elm
Note
When using
ssh, it will automatically detect your key under~/.ssh. You can specify a key with-i /path/to/my/key.You can now type your UNF password.
On your computer, you will see a new file
~/.ssh/known_hosts. It contains all the servers that you connected to.
Note
You can also connect to a server via its public IP in the form XXX.XX.XX.XX
A few tips¶
Automatic authentification¶
Every time you login to a server, you will be asked for the password if available. To avoid that, you can add your public key so the server doesn’t need your password to prove ownership.
Send your public key to the server,
ssh-copy-id <you_username>@elm
After log-in to the server, you will be asked for your password a last time. Whenever you log-in again, it should not ask for it.
ssh <your_username>@elm
You can check the file
~/.ssh/authorized_keyson the server, it should match your public keyid_rsa.pub.
Easy ssh¶
It can be cumbersome to type the ssh command if you have lot of arguments.
For example, let’s say you want to set-up port forwarding on a specific server with a specific user, you would need to type:
ssh -L 1234:localhost:80 -i ~/.ssh/root/id_root root@server2.domain.cloud.com
It is possible to put all the options inside a single file in ~/.ssh/config, and call ssh with a single command.
For example, you would call the previous command with just:
ssh server1
With this ~/.ssh/config:
1 2 3 4 5 6 7 8 9 Host server1 HostName server2.domain.cloud.com User root IdentityFile ~/.ssh/root/id_root LocalForward 1234 localhost:80 Host server2 HostName 200.00.00.00 User ubuntu
Enabling display¶
Though it is not recomended because of performance, you can log in while enabling display by using the x11 forwarding option ssh -X.
This can be usefull if you are running MATLAB for example and need the graphical interface.
Note
The server maybe doesn’t allow display, this can be checked from X11Forwarding option in /etc/ssh/sshd_config (if you are root).
Questions ?¶
If you have any issues with ssh, you can ask on the SIMEXP lab slack in #neuroinformatics channel!