11-12-2007
Quote:
Originally Posted by
Smiling Dragon
Short answer: No sorry.
The passphrase would be on the client side anyway (to decrypt their private key) so couldn't be trusted by the sshd end.
I'd suggest sticking with NOPASSWD if you really can't have a local password for the user (I fail to see why this needs to be that way though...)
Thank you for quick reply.
The reason we dont have passwords in passwd is because the customer have a lot of servers but no directoryservice like LDAP, NIS+. And when we install the servers we add all the users and set up ssh for them. Hopefully they soon will start to use LDAP and our task will be a lot easier.
/Jocke
10 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
ok...I'm stumped on this one. I cannot figure out how to carry over my environment variables with a sudo command. I need to install an application under root and only have sudo access to get there. I can use ssh -Y <host> and launch an xwindows session successfully as myself but as soon as I sudo... (3 Replies)
Discussion started by: scottsl
3 Replies
2. UNIX for Advanced & Expert Users
Hi,
I would like to know how i can perform a task, while performing ssh, sudo and command at the same time.
What I generally do is I ssh to the server, where i created private and public, so it does not prompt me for password all the time. Then i need to run "sudo su - ldaprole" to get into... (9 Replies)
Discussion started by: john_prince
9 Replies
3. UNIX for Advanced & Expert Users
Hi,
I am trying to execute some command, via ssh and sudo.
Here is what i want to do.
ssh localhost | sudo su - ldaprole | ls -ltrh
However, this command gives me listing of my home directory, and not of ldaprole.
If I logic directly, when i perform sudo su - ldaprole, it... (5 Replies)
Discussion started by: john_prince
5 Replies
4. Shell Programming and Scripting
I am writing a BASH script to update a webserver and then restart Apache. It looks basically like this:
#!/bin/bash
rsync /path/on/local/machine/ foo.com:path/on/remote/machine/
ssh foo.com sudo /etc/init.d/apache2 reloadrsync and ssh don't prompt for a password, because I have DSA encryption... (9 Replies)
Discussion started by: fluoborate
9 Replies
5. Programming
Is there a way to transfer my sudo password via ssh so that I can copy files remotely and pass them locally, so:
cat sudo-passwd-file|ssh -t user@10.7.0.180 'sudo find / -depth|cpio -oacv|gzip' > /path/to/dir/file.cpio.gz
I am in the process of a creating a script. Everytime I try and just... (16 Replies)
Discussion started by: metallica1973
16 Replies
6. Red Hat
I am not sure what I am missing here. I have the following identical entry in /etc/sudoers on multiple Red Hat 6.4 servers.
icinga ALL=NOPASSWD:/usr/bin/yum --security --exclude\="kernel*" check-update
On one server when I enter the command over SSH as follows it works fine.
ssh -t -q... (1 Reply)
Discussion started by: scotbuff
1 Replies
7. Shell Programming and Scripting
when the following command is issued the command prompt is received, how do I get past this?
ssh -t usera@hosta sudo su - userb -c id (4 Replies)
Discussion started by: squrcles
4 Replies
8. Shell Programming and Scripting
Hi Experts,
I am new to Shell scripting. I want to login to a server using a script. The normal command I use is --> sudo ssh <Servername> . when i tried putting this into a txt format file and tried running, it throw an error "can't execute". I am an Admin and i have root access. Any help would... (6 Replies)
Discussion started by: Tom1989
6 Replies
9. Cybersecurity
I'm confused in the configuration of sudoers for one group of users.
The users need to execute a app from a remote machine, in this local machine they want me to allow ssh for them using sudo
for eg. sudo -u admin ssh -X euadmin@<IP address of remote> <remote script which opens a gui>
It... (1 Reply)
Discussion started by: anandk
1 Replies
10. Shell Programming and Scripting
Hey everybody,
currently I am having an issue that I need to open an ssh session to a remote host, once on the remote host I need to use sudo and then execute sqlplus. Once the sqlplus call is open I need to execute one command while the sqlplus is active. For example show sga.
I already got so... (3 Replies)
Discussion started by: h1kelds
3 Replies
LEARN ABOUT DEBIAN
ssh-askpass-fullscreen
SSH-ASKPASS-FULLSCREEN(1) General Commands Manual SSH-ASKPASS-FULLSCREEN(1)
NAME
ssh-askpass-fullscreen - A simple replacement for ssh-askpass written with gtk2
SYNOPSIS
ssh-askpass-fullscreen
DESCRIPTION
This manual page was written for the Debian distribution because the original program does not have a manual page.
gnome-ssh-askpass is a GNOME-based passphrase dialog for use with OpenSSH. It is intended to be called by the ssh-add(1) program and not
invoked directly. It allows ssh-add(1) to obtain a passphrase from a user, even if not connected to a terminal (assuming that an X display
is available). This happens auto-matically in the case where ssh-add is invoked from one's ~/.xsession or as one of the GNOME startup pro-
grams, for example.
In order to be called automatically by ssh-add, ssh-askpass-fullscreen should be installed as /usr/bin/ssh-askpass
ssh-askpass-fullscreen is a program that...
ENVIRONMENT VARIABLES
The following environment variables are recognized:
GNOME_SSH_ASKPASS_GRAB_SERVER
Causes gnome-ssh-askpass to grab the X server before asking for a passphrase.
GNOME_SSH_ASKPASS_GRAB_POINTER
Causes gnome-ssh-askpass to grab the mouse pointer will be grabbed too.
These may have some benefit to security if you don't trust your X server. Keyboard is always grabbed.
SEE ALSO
ssh-add(1), ssh-askpass(1).
AUTHOR
This manual page was written by Marco Presi (Zufus) <zufus@debian.org>, for the Debian GNU/Linux system (but may be used by others) and it
is based on that for x11-ssh-askpass by Philip Hands and the one for gnome-ssh-askpass by Colin Watson <cjwatson@debian.org>
May 8 , 2004 SSH-ASKPASS-FULLSCREEN(1)