<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>/ Andreas &#124; System administrator / &#187; ssh</title>
	<atom:link href="http://blog.bogosity.se/tag/ssh/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.bogosity.se</link>
	<description></description>
	<lastBuildDate>Sat, 14 Jan 2012 11:50:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.bogosity.se' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>/ Andreas &#124; System administrator / &#187; ssh</title>
		<link>http://blog.bogosity.se</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.bogosity.se/osd.xml" title="/ Andreas &#124; System administrator /" />
	<atom:link rel='hub' href='http://blog.bogosity.se/?pushpress=hub'/>
		<item>
		<title>/etc/init.d/autossh_tunnel.foo</title>
		<link>http://blog.bogosity.se/2008/08/27/etcinitdautossh_tunnelfoo/</link>
		<comments>http://blog.bogosity.se/2008/08/27/etcinitdautossh_tunnelfoo/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 17:56:46 +0000</pubDate>
		<dc:creator>Andreas</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[autossh]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[tunnel]]></category>

		<guid isPermaLink="false">http://www.andreasolsson.se/2008/08/27/etcinitdautossh_tunnelfoo/</guid>
		<description><![CDATA[Autossh is a nice way to keep a ssh connection alive. This is especially useful when it comes to ssh tunnels. To make things even more automagicial I have now written the init script template autossh_tunnel.foo. A few import facts regarding the script: Autossh 1.4 or later is required. Earlier versions of autossh doesn&#8217;t handle [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=31&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.harding.motd.ca/autossh/">Autossh</a> is a nice way to keep a ssh connection alive. This is especially useful when it comes to ssh tunnels. To make things even more automagicial I have now written the init script template <a href="http://files.bogosity.se/autossh_tunnel.foo" title="autossh_tunnel.foo">autossh_tunnel.foo</a>.</p>
<p>A few import facts regarding the script:</p>
<ul>
<li>Autossh 1.4 or later is required. Earlier versions of autossh doesn&#8217;t handle PID-files.</li>
<li>The init script is based on the <em>start-stop-daemon</em>. Hence it will probably only work on Debian, Ubuntu and similar systems.</li>
<li>There is no way to enter a password. A setup based on ssh-keys or similar is required.</li>
<li>Autossh doesn&#8217;t handle every kind of ssh problem. Because of that it is possible for the initial connection to fail without the init script knowing about it.</li>
</ul>
<p>This is by the way my first real init script. Any feedback on it would be greatly appreciated.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/andolsys.wordpress.com/31/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/andolsys.wordpress.com/31/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andolsys.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andolsys.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andolsys.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=31&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.bogosity.se/2008/08/27/etcinitdautossh_tunnelfoo/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b8504423137e4de7ddd0aa67a628fe18?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andolsys</media:title>
		</media:content>
	</item>
		<item>
		<title>Debian – Ubuntu, S/Key and OPIE</title>
		<link>http://blog.bogosity.se/2008/05/31/debian-ubuntu-skey-and-opie/</link>
		<comments>http://blog.bogosity.se/2008/05/31/debian-ubuntu-skey-and-opie/#comments</comments>
		<pubDate>Sat, 31 May 2008 11:12:30 +0000</pubDate>
		<dc:creator>Andreas</dc:creator>
				<category><![CDATA[Howto]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[OPIE]]></category>
		<category><![CDATA[OTP]]></category>
		<category><![CDATA[PAM]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.andreasolsson.se/2008/05/31/debian-ubuntu-skey-and-opie/</guid>
		<description><![CDATA[Been looking for a simple way to enabling  S/Key support in Linux. Once I found out the magical keyboards being OPIE and PAM it became almost trivial to allow ssh-logins using One Time Passwords (OTP). The following instructions are specifically written to apply on Debian and Ubuntu. On a general note the concept should work [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=27&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Been looking for a simple way to enabling  <a href="http://en.wikipedia.org/wiki/S/Key">S/Key</a> support in Linux. Once I found out the magical keyboards being OPIE and PAM it became almost trivial to allow ssh-logins using One Time Passwords (OTP).</p>
<p>The following instructions are specifically written to apply on Debian and Ubuntu. On a general note the concept should work on any Linux system using OpenSSH and PAM.</p>
<p>First of all you should install the package <em>opie-server</em>. It will give you the necessary PAM-module and some accompanying tools.</p>
<p>Now edit <em>/etc/pam.d/ssh</em>, remove (comment) the inclusion of common-auth, and add these lines.</p>
<blockquote><p>auth       sufficient pam_unix.so<br />
auth       sufficient pam_opie.so<br />
auth       required  pam_deny.so</p></blockquote>
<p>If you only want allow OTP-logins; this line will do.</p>
<blockquote><p>auth       required   pam_opie.so</p></blockquote>
<p>Next it&#8217;s time to edit <em>/etc/ssh/sshd_config</em>.</p>
<blockquote><p>ChallengeResponseAuthentication yes</p></blockquote>
<p>That&#8217;s it. Restart your sshd and it will be ready to accept OTP-logins. To initialize a user; run <em>opiepasswd</em> (equivivalent of keyinit). Responses are generated using <em>opiekey</em>.</p>
<p>Client-side it&#8217;s usually enough to install the package <em>opie-client</em>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/andolsys.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/andolsys.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andolsys.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andolsys.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andolsys.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=27&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.bogosity.se/2008/05/31/debian-ubuntu-skey-and-opie/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b8504423137e4de7ddd0aa67a628fe18?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andolsys</media:title>
		</media:content>
	</item>
		<item>
		<title>line_removal.pl (known_hosts)</title>
		<link>http://blog.bogosity.se/2008/05/16/line_removalpl-known_hosts/</link>
		<comments>http://blog.bogosity.se/2008/05/16/line_removalpl-known_hosts/#comments</comments>
		<pubDate>Thu, 15 May 2008 23:35:10 +0000</pubDate>
		<dc:creator>Andreas</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.andreasolsson.se/2008/05/16/line_removalpl-known_hosts/</guid>
		<description><![CDATA[Manually removing entries from your known_hosts doesn&#8217;t take my of an effort. Still, it&#8217;s something you can grow tired of. Especially so after resent events (DSA-1571). That is why I&#8217;ve now written my very own line_removal.pl  script. Basically you feed the script one or more line numbers. Corresponding lines in your ~/.ssh/known_hosts will then be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=23&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Manually removing entries from your <em>known_hosts</em> doesn&#8217;t take my of an effort. Still, it&#8217;s something you can grow tired of. Especially so after resent events (<a href="http://www.debian.org/security/2008/dsa-1571">DSA-1571</a>). That is why I&#8217;ve now written my very own <a href="http://files.bogosity.se/line_removal.pl" title="line_removal.pl">line_removal.pl</a>  script.</p>
<p>Basically you feed the script one or more line numbers. Corresponding lines in your <em>~/.ssh/known_hosts</em> will then be deleted.</p>
<blockquote><p>andreas@leto:~$ ./line_removal.pl 22<br />
Removing line #22 from /home/andreas/.ssh/known_hosts</p>
<p>andreas@leto:~$ ./line_removal.pl 3 37 29<br />
Removing line #37 from /home/andreas/.ssh/known_hosts<br />
Removing line #29 from /home/andreas/.ssh/known_hosts<br />
Removing line #3 from /home/andreas/.ssh/known_hosts</p></blockquote>
<p>To be honest I really don&#8217;t know if I&#8217;ll ever use this script against more than one line at a time. Somehow it still seemed wrong not to support the option of feeding it multiple arguments.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/andolsys.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/andolsys.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andolsys.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andolsys.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andolsys.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.bogosity.se&amp;blog=3175717&amp;post=23&amp;subd=andolsys&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.bogosity.se/2008/05/16/line_removalpl-known_hosts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b8504423137e4de7ddd0aa67a628fe18?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">andolsys</media:title>
		</media:content>
	</item>
	</channel>
</rss>
