4 msgThis is an very serious bug
2 msgRe: [SECURITY] [DSA-1236-1] New enemies-of-carl...
1 msg28.082.006 Risiko bancario/ Sanpaolo-Intesa, un...
1 msgNeed UpdateS uncorpmetway Banking.
5 msgUnable to write files greater than 1GB to udf-f...
1 msgRe: [SECURITY] [DSA 1233-1] New Linux 2.6.8 pac...
1 msgAlmost free software, but licensed? Unreal? No!...
2 msgRe: Clam AntiVirus Base64 MIME Attachments Deni...
1 msgGestion des quotas
1 msgRe: [SECURITY] [DSA-1230-1] new l2tpns packages...
3 msgRe: [SECURITY] [DSA 1232-1] New clamav packages...
1 msggoal games
1 msgwent parole
1 msgAlexander Jäger is out of the office.
9 msgRe: Bug#401969: please build using hunspell
1 msgUpdated gnupg package for sarge
1 msgRe: [SECURITY] [DSA 1228-1] New elinks packages...
8 msgRe: <Mudança de e-mail - e-mail change>

creative ssh-agent uses
\ Ratiu Petru (4 Dec 2006)
. \ Adrian von Bidder (7 Dec 2006)
. \ Stefan Denker (7 Dec 2006)
. . \ Ratiu Petru (7 Dec 2006)
. \ Rudi Cilibrasi (9 Dec 2006)
. . \ Brett Parker (9 Dec 2006)
. . \ Ratiu Petru (9 Dec 2006)
. . . \ horst (10 Dec 2006)

3 msgRe: [SECURITY] [DSA 1222-1] New proftpd package...
Subject:creative ssh-agent uses
Group:Debian-security
From:Ratiu Petru
Date:4 Dec 2006


 
It all started when i wanted to use a encrypted filesystem for my personal
backups: I have a script that I run after I log in to the backup server, it
asks me the passphrase for the encrypted storage, mounts it, and begins the
rsync-over-ssh backup script which connects back to my workstation, all
thanks to ssh-agent.

I'd like to skip the "enter the crypto password" bit. Can it not be done
with ssh-agent too? Cryptsetup can read the key from stdin, so all it's left
is to provide something that identifies me as the owner of the forwarded
ssh-agent and the backup session.

According to what I read until now, authentication works by sending some
random challenge to ssh-agent via the SSH_AUTH_SOCK socket, reading the
response and applying the public key to it to verify it. Unfortunately, all
this is done internally by sshd (if i'm not mistaken), with no way to
control or see the challenge or the response.

What I'm thinking is to provide a static string as a challenge and use the
response as the cryptodevice password, but I can't find a program that
allows me to manipulate the socket this way. This mechanism might also be
used for other purposes, stacking public key authentication in a "normal"
password-based login.

I guess I am either missing an obvious security flaw to this, or it's
unnecessarily complicated, because it seems there's no way to do this via
standard programs. Of course, I might have just missed it ;-) Please help me
shed some light on this.


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com