data:image/s3,"s3://crabby-images/4399a/4399afe51d0a71955c3f0987552fb0250e7f8d65" alt="Cray Urika-GX Administration Manual Download Page 182"
●
User access level - Determines if a given user is constrained to working within a tenant Virtual Machine
(restricted access) or permitted access to physical nodes on the Urika-GX (relaxed access)
●
System service mode - Determines if the system is strictly enforcing policies (secure mode) or relaxing
policy enforcement (default mode)
For more information, refer to
on page 177
7.4
Set up Passwordless SSH
About this task
Follow this procedure if the home directory does not contain a
.ssh
file with an
rsa_id.pub
in it.
Procedure
1. Log on to the tenant virtual machine.
2. Generate a public/private RSA key pair.
$
ssh-keygen
Enter file in which to save the key (/home/users/erl/.ssh/id_rsa):
Created directory '/home/users/erl/.ssh'.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/users/erl/.ssh/id_rsa.
Your public key has been saved in /home/users/erl/.ssh/id_rsa.pub.
The key fingerprint is:
ab:26:a2:a6:a2:ee:0a:fe:08:37:d4:a8:ff:f7:74:35 erl@erics_soc
The key's randomart image is:
+--[ RSA 2048]----+
| |
| |
| |
| o |
| o . S E |
| o . . . |
|+ o o . |
|=+o.. oo . |
|&*o+.+... |
+-----------------+
$
cat .ssh/id_rsa.pub >> .ssh/authorized_keys
$
ssh localhost "echo success"
The authenticity of host 'localhost (::1)' can't be established.
ECDSA key fingerprint is fa:86:a7:9c:6c:d3:f2:2e:25:12:3f:27:2c:c2:f9:13.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'localhost' (ECDSA) to the list of known hosts.
success
3. Execute the following if the home directory does have a
.ssh
directory with an
id_rsa.pub
in it but it is not
possible to login to localhost without a password:
$
cat .ssh/id_rsa.pub >> .ssh/authorized_keys
$
ssh localhost "echo success"
Security
S3016
182