Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
SSH That Wonderful Thing
Search
Marc Cluet
June 09, 2013
Technology
100
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
SSH That Wonderful Thing
Marc Cluet
June 09, 2013
More Decks by Marc Cluet
See All by Marc Cluet
FOSDEM'14 - Autoscaling Best Practices
lynxman
1
130
A metadata ocean in Chef and Puppet
lynxman
0
67
Rackspace Hack Night - Vagrant & Packer
lynxman
0
160
Innovation in the Cloud - Rackspace Zurich Event
lynxman
0
110
Introduction to DevOps - Rackspace Tech Night
lynxman
1
88
Introduction To Hadoop
lynxman
1
120
Hadoop Operations
lynxman
0
130
Networking & DNS 101
lynxman
0
110
Juju and Puppet - Rapid Harmonious Deployment
lynxman
0
110
Other Decks in Technology
See All in Technology
Data Hubグループ 紹介資料
sansan33
PRO
0
3.2k
AWSとAzureのマルチクラウド活用における強い味方___AWS_Kiroを使った二刀流スキル作成.pdf
duelist2020jp
1
140
会計事務所と顧問先の契約関係をOIDC・OAuthで表現する
terara
0
500
Bill One 開発エンジニア 紹介資料
sansan33
PRO
7
20k
OAuth SPIFFE Client Authentication(OAuth/OIDC Numa (Immersion) Workshop 2026)
oidfj
PRO
0
350
AIレビュー時代に必要なのは、SLOで引く撤退ライン
nobuoooo
0
150
AI駆動開発をチームに根付かせる - 「1行も書かない」チームがHarnessを育てた1年 -
kenichirokimura
6
3.3k
Eight Engineering Unit 紹介資料
sansan33
PRO
3
8.3k
Distributed Transactions Under Fire: Building a Zero-Oversell Flash Sale Platform with Amazon Aurora DSQL
yama3133
1
110
みてねにおけるAI-DLC導入活動とAIドリブン開発の現在地/JAWS-UG AI-DLC #2
isaoshimizu
2
290
tamachi.goを支える技術
rymiyamoto
0
110
Digital Credentials API × OpenID4VP ブラウザ完結型本人確認の実装知見(OAuth/OIDC Numa (Immersion) Workshop 2026)
oidfj
PRO
0
340
Featured
See All Featured
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Navigating Algorithm Shifts & AI Overviews - #SMXNext
aleyda
1
1.6k
A Guide to Academic Writing Using Generative AI - A Workshop
ks91
PRO
1
390
Optimizing for Happiness
mojombo
378
71k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.9k
How to train your dragon (web standard)
notwaldorf
97
6.8k
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
240
Agile Actions for Facilitating Distributed Teams - ADO2019
mkilby
0
260
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
310
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2.2k
What Being in a Rock Band Can Teach Us About Real World SEO
427marketing
0
1.1k
Balancing Empowerment & Direction
lara
6
1.3k
Transcript
Marc Cluet – Lynx Consultants How I learned to
stop worrying and love the shell
What we’ll cover? ¡ Understand how SSH works ¡
Get a clear picture of how ssh bastion hosts work ¡ Be able to do more awesome stuff with SSH! Lynx Consultants © 2013
What is SSH? ¡ Secure Shell (SSH) is a cryptographic
network protocol for secure data communication, remote shell services or command execution and other secure network services between two networked computers that it connects via a secure channel over an insecure network: a server and a client (running SSH server and SSH client programs, respectively).[1] The protocol specification distinguishes two major versions that are referred to as SSH-‐1 and SSH-‐2…. *whew* Lynx Consultants © 2013
But really, what is SSH? ¡ SSH opens a terminal
connection to a remote host ¡ It does so using cryptography to avoid any break or leak in communication ¡ It is a very powerful tool for remote execution ¡ It is awesome! Lynx Consultants © 2013
How does SSH create a connection? ¡ You run your
SSH command ssh user@host ¡ SSH client connects to host ¡ SSH client negotiates with host crypto and version ¡ SSH host requests authentication (password, certificates) ¡ SSH client replies with the crypto challenge ¡ Communication is open! Lynx Consultants © 2013
Authentication methods ¡ Password § Typical manual password
§ Turing keyboard test ¡ Certificates § Public Key certificates (RSA1, RSA, DSA, GSS) § Host-‐based certificates Lynx Consultants © 2013
Certificates ¡ A certificate ensures your identity by providing a
crypto key divided in public and private parts (asymmetric cryptography) ¡ A public crypto key can be shared and is mathematically linked to the private key ¡ A private key shouldn’t be shared and is able to unlock and decipher the ciphertext Lynx Consultants © 2013
Certificates ¡ A certificate can be generated for each host
or group of hosts you want to access ¡ Each certificate can and should be protected by a password for extra security ¡ Certificates are easy to revoke, so in case of any incident a new certificate can be generated Lynx Consultants © 2013
Certificates ¡ Run the command § ssh-‐keygen –t rsa
~/.ssh/id_foryournetwork ¡ This will create a unique certificate for network hosts ¡ All your other hosts or keys (github, etc) are safely different Lynx Consultants © 2013
Security risks of running an infrastructure ¡ If we leave
password authentication open we’re subject to dictionary attacks § The whole system strength is defined by the weakest password ¡ Each host that has ssh open is another security risk ¡ All this can be resolved by Bastion Hosts! Lynx Consultants © 2013
What is a Bastion Host? Lynx Consultants © 2013
What is a Bastion Host? ¡ A Bastion Host sits
between two networks, one trusted and one untrusted ¡ It regulates traffic between those networks, highlighting any malicious traffic and refusing it ¡ It is the first line of defence in a system Lynx Consultants © 2013
SSH Configuration ¡ Here’s an example # Config to
access bastion host! Host bastionhost! !User myuser! !IdentityFile ~/.ssh/id_mynetwork! !Hostname 1.2.3.4! Lynx Consultants © 2013
How to Diagnose connections ¡ Always run ssh –v (-‐v
for verbose) ¡ Make sure you test each point of your connection Lynx Consultants © 2013
How to Diagnose connections ¡ Always run ssh –v (-‐v
for verbose) ¡ Make sure you test each point of your connection § First bastion host § Then proceed further up ¡ Regular issues § Lack of Certificate § DNS problem § Internets is broken Lynx Consultants © 2013
Awesome Stuff – Port Redirection ¡ You can redirect a
port from your machine to the remote host or the other way around § -‐L myport:destination:destport ▪ Forwards a connection made to localhost 8080 to myhost port 80 (-‐ L 8080:myhost:80) Lynx Consultants © 2013
Awesome Stuff – Port Redirection ¡ You can redirect a
port from your machine to the remote host or the other way around § -‐R remoteport:destination:destport ▪ Forwards a connection made to destination port 8080 to localhost port 80 (-‐R 80:myhost:8080) Lynx Consultants © 2013
Awesome Stuff – Socks Proxy ¡ You can create a
SOCKS Proxy transparently with SSH § This will allow you to navigate the remote network as if it was your own ¡ ssh –D2222 user@myhost ¡ Configure your browser to use a SOCKS proxy at localhost port 2222 ¡ Navigate to all internal network pages! Lynx Consultants © 2013
Questions? Lynx Consultants © 2013