What is the difference between /etc/ssh/ and ~/.ssh?

Tags
key-value pairs, linux, openssh, solved, ssh

 
Thread Tools Search this Thread
# 1  
Old 04-23-2018
What is the difference between /etc/ssh/ and ~/.ssh?

Hi,

I know the “/etc/ssh” directory is for the ssh daemon and the “~/.ssh” directory is for a particular user.

Both directories contain private and public keys: (see the attachment)

but what is the difference between those keys in both directories? I’m confused because the ones i use as a user, is in my home directory ~/.ssh, and what are the roles of the keys found in /etc/ssh ? for what purpose are they created for ?

Thanks.
What is the difference between /etc/ssh/ and ~/.ssh?-screen-shot-2018-04-23-18-08-06-png
# 2  
Old 04-23-2018
The files in /etc/ssh are for the service on the server you are connecting to. it uses them to listen and exchanges keys with the client session so that the data is encrypted.

Your personal keys (as you know in ~/.ssh) provide the reverse.

When you request a connection (before signing on or anything) the server listening (default on port 22) will pass you its public key for the server. This key enables you to encrypt traffic that only the server can decrypt. You can also use this public key to verify that you have connected to the correct server. The first time, you open a connection, you will be asked to confirm the key provided by the server. If you accept, this is stored in ~/.ssh/knwon_hosts so that you can be sure you are connecting the the same server on a later occasion.

See this article for more information - 17.3. Event Sequence of an SSH Connection



I hope that this helps. If not, feel free to ask again.


Kind regards,
Robin
This User Gave Thanks to rbatte1 For This Post:
kavish11 (04-24-2018)
# 3  
Old 04-23-2018
Oh ok. Now i get it. When i try to connect to a server, the server will send me its public key from/etc/ssh. But what is the purpose of the keys from ~/.ssh ? It seems like they are not used.

Here's the scenerio:

I have two virtual machines open side by side - Server_A and Server_B. I tried to access Server_B from Server_A. Now Server_B will send me its public key from /etc/ssh.

Now the public key of Server_B will be in ~/.ssh/known_hosts file.

Again the keys found in my ~/.ssh directory are not used. I just don't get it.

---------- Post updated at 10:51 PM ---------- Previous update was at 09:45 PM ----------

I did some research, and i've found that if i try to connect to a server with the private and public keys from my ~/.ssh directory i have to copy the public key to server's authorized_keys file (using either ssh-copy-id or scp). Is that correct ?
# 4  
Old 04-23-2018
The next connection will compare the server's public host key with the one in known_hosts.
If different it will warn "host key changed, perhaps a man-in-the-middle attack".
--
To complete your confusion, there is also an optional /etc/ssh/known_hosts. Here the administrator can store public host keys that are valid for all the users on the system, so they do not need to store them in their ~/.ssh/known_hosts.
--
Extra user keys that you put in ~/.ssh/ can be used to replace a password login (enabling a password-less login). The accepted public user keys are stored on the accessing side in ~/ssh/authorized_key (or ~/ssh/authorized_key2, dependent on the ssh version).
This User Gave Thanks to MadeInGermany For This Post:
kavish11 (04-24-2018)
# 5  
Old 04-23-2018
Quote:
Originally Posted by kavish11
Oh ok. Now i get it. When i try to connect to a server, the server will send me its public key from/etc/ssh. But what is the purpose of the keys from ~/.ssh ? It seems like they are not used.
~/.ssh/known_hosts is used by the client alone, to identify servers the client has connected to before.

~/.ssh/authorized_keys is used by the server being connected to, when you ssh into that user using a key. So in that sense it's still a client setting, though it's the server which must read it.

~/.ssh/id_rsa, ~/.ssh/id_rsa etc are used by a client when connecting to a server. That is the file which the server you're connecting to recognizes via the other end's ~/.ssh/authorized_keys . There's various kinds of possible keys, some obsolete, some modern, so there's actually a few different names ssh will use by default there.

I'm sure there's other things which may end up in ~/.ssh/ also. It's a place for client settings, not something simple and single-purpose.
This User Gave Thanks to Corona688 For This Post:
kavish11 (04-24-2018)
# 6  
Old 04-24-2018
It all make sense now. Thank you everyone.

|
Thread Tools Search this Thread
Search this Thread:
Advanced Search

More UNIX and Linux Forum Topics You Might Find Helpful
Find active SSH servers w/ ssh keys on LAN syrius Shell Programming and Scripting 11 11-06-2018 01:45 PM
Ssh script to validate ssh connection to multiple serves with status sreeram4 UNIX for Beginners Questions & Answers 3 06-04-2018 10:30 AM
Connection SSH to remote by ssh aroucasp BSD 1 03-07-2018 04:19 AM
Check if file exists via ssh in ssh (nested) say170 Shell Programming and Scripting 2 10-23-2014 05:31 PM
SSH tunnel working for ssh but not for sshfs Vathau UNIX for Dummies Questions & Answers 1 02-19-2013 12:04 PM
Ssh = ssh expect and keep everything not change include parameter postion yanglei_fage Shell Programming and Scripting 1 12-27-2012 12:34 PM
SSH SSH encountered 1 errors during the transfer Computergal2104 UNIX for Dummies Questions & Answers 1 08-10-2012 11:08 AM
Automate ssh between different flavours of ssh kamitsin AIX 1 06-22-2011 03:09 AM
what is the difference between openssh and ssh package installed with Solaris box chidori Solaris 2 06-10-2011 11:33 AM
Bash commands to an 'ssh' within an ssh' mcintosh.jamie Shell Programming and Scripting 7 01-15-2010 07:17 PM
Using ssh to add register key on ssh server leaftree Shell Programming and Scripting 9 12-22-2009 02:55 PM
could not send commands SSH session with Net::SSH::Expect hansini Shell Programming and Scripting 0 08-28-2009 01:56 AM
difference between logging into unix through f-secure ssh client and telnet trichyselva UNIX for Advanced & Expert Users 1 09-02-2008 03:31 AM
What's the difference between an SSH Client and an SSH Server? PSC Security 1 07-19-2004 04:24 PM