Michael_ich Posted November 2, 2020 Posted November 2, 2020 (edited) Здраствуйте, уважаемые форумчане. Знаю, обсуждалось, было. Читал, смотрел, искал, но успеха не добился. Подскажите как авторизоваться без пароля (по shh) на интрент центре? Поставил entware по этой инструкции. Сгенерировал ключи. Перенес на интрент центр ssh-copy-id -i /config/.ssh/id_rsa.pub root@192.168.1.1 -p 222 Без пароля не заработало ssh -i /config/.ssh/id_rsa root@192.168.1.1 -p 222 Передвинул ключи mv /opt/root/.ssh/authorized_keys /opt/etc/dropbear Снова попытался выполнить ssh -i /config/.ssh/id_rsa root@192.168.1.1 -p 222 Не срабатывает. Команды cd /opt/etc/dropbear/ chmod 600 authorized_keys выполнял. Что может быть не так? Интрент центр перезагружал. Как отдельно перезагрузить dropbear не знаю. Edited November 2, 2020 by Michael_ich 1 Quote
vasek00 Posted November 3, 2020 Posted November 3, 2020 Если речь про Entware весь запуск сервисов в /opt/etc/init.d там же и S..drobear т.е. S..drobear restart 1 Quote
Michael_ich Posted November 9, 2020 Author Posted November 9, 2020 (edited) Проблема похоже оказалась в параметрах запуска dropbear. нужно указать -s в /opt/etc/init.d/SXXdropbear (где ХХ - две цифры исходя из конкретной конфигурации) нужно исправить функцию start() на $DROPBEAR -s -p $PORT -P $PIDFILE Но тогда не зайти по паролю. А мне нужно и по паролю и по ключу. UPDT Тут мне подсказали, что ключи openssh не подходят к dropbear Видимо в этом проблема Edited November 9, 2020 by Michael_ich Quote
rustrict Posted November 10, 2020 Posted November 10, 2020 17 часов назад, Michael_ich сказал: UPDT Тут мне подсказали, что ключи openssh не подходят к dropbear Видимо в этом проблема Это не так: Compatible with OpenSSH ~/.ssh/authorized_keys public key authentication Я вам в другой теме предложил посмотреть лог подключения. Проверьте, например, что в ряду PreferredAuthentications publickey стоит впереди password: debug3: preferred publickey,keyboard-interactive,password Quote
Michael_ich Posted November 10, 2020 Author Posted November 10, 2020 1 hour ago, rustrict said: Это не так: Compatible with OpenSSH ~/.ssh/authorized_keys public key authentication Я вам в другой теме предложил посмотреть лог подключения. Проверьте, например, что в ряду PreferredAuthentications publickey стоит впереди password: debug3: preferred publickey,keyboard-interactive,password Выдает следующее Spoiler bash-5.0# ssh -p '222' 'root@192.168.1.1' -vvv OpenSSH_8.3p1, OpenSSL 1.1.1g 21 Apr 2020 debug1: Reading configuration data /etc/ssh/ssh_config debug2: resolve_canonicalize: hostname 192.168.1.1 is address debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug2: ssh_connect_direct debug1: Connecting to 192.168.1.1 [192.168.1.1] port 222. debug1: Connection established. debug1: identity file /root/.ssh/id_rsa type 0 debug1: identity file /root/.ssh/id_rsa-cert type -1 debug1: identity file /root/.ssh/id_dsa type -1 debug1: identity file /root/.ssh/id_dsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa type -1 debug1: identity file /root/.ssh/id_ecdsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa_sk type -1 debug1: identity file /root/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /root/.ssh/id_ed25519 type -1 debug1: identity file /root/.ssh/id_ed25519-cert type -1 debug1: identity file /root/.ssh/id_ed25519_sk type -1 debug1: identity file /root/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /root/.ssh/id_xmss type -1 debug1: identity file /root/.ssh/id_xmss-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.3 debug1: Remote protocol version 2.0, remote software version dropbear debug1: no match: dropbear debug2: fd 3 setting O_NONBLOCK debug1: Authenticating to 192.168.1.1:222 as 'root' debug3: put_host_port: [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:1 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug3: order_hostkeyalgs: prefer hostkeyalgs: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521 debug3: send packet: type 20 debug1: SSH2_MSG_KEXINIT sent debug3: receive packet: type 20 debug1: SSH2_MSG_KEXINIT received debug2: local client KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c debug2: host key algorithms: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,sk-ssh-ed25519@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: compression ctos: none,zlib@openssh.com,zlib debug2: compression stoc: none,zlib@openssh.com,zlib debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug2: peer server KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,kexguess2@matt.ucc.asn.au debug2: host key algorithms: ssh-ed25519,ecdsa-sha2-nistp256,rsa-sha2-256,ssh-rsa debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes256-ctr debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes256-ctr debug2: MACs ctos: hmac-sha1,hmac-sha2-256 debug2: MACs stoc: hmac-sha1,hmac-sha2-256 debug2: compression ctos: none debug2: compression stoc: none debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug3: send packet: type 30 debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug3: receive packet: type 31 debug1: Server host key: ecdsa-sha2-nistp256 SHA256:9BWRfXLc3Nkgef3/ZH1AjLxYkPYXXGpvWSlXQnOhFHU debug3: put_host_port: [192.168.1.1]:222 debug3: put_host_port: [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:1 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:1 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug1: Host '[192.168.1.1]:222' is known and matches the ECDSA host key. debug1: Found key in /root/.ssh/known_hosts:1 debug3: send packet: type 21 debug2: set_newkeys: mode 1 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug3: receive packet: type 21 debug1: SSH2_MSG_NEWKEYS received debug2: set_newkeys: mode 0 debug1: rekey in after 134217728 blocks debug1: Will attempt key: /root/.ssh/id_rsa RSA SHA256:qvRNyydFqnVmaBYZkH3+GHFpnPZt5R1YmenSJfpI2KM debug1: Will attempt key: /root/.ssh/id_dsa debug1: Will attempt key: /root/.ssh/id_ecdsa debug1: Will attempt key: /root/.ssh/id_ecdsa_sk debug1: Will attempt key: /root/.ssh/id_ed25519 debug1: Will attempt key: /root/.ssh/id_ed25519_sk debug1: Will attempt key: /root/.ssh/id_xmss debug2: pubkey_prepare: done debug3: send packet: type 5 debug3: receive packet: type 7 debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,rsa-sha2-256,ssh-rsa> debug3: receive packet: type 6 debug2: service_accept: ssh-userauth debug1: SSH2_MSG_SERVICE_ACCEPT received debug3: send packet: type 50 debug3: receive packet: type 51 debug1: Authentications that can continue: publickey,password debug3: start over, passed a different list publickey,password debug3: preferred publickey,keyboard-interactive,password debug3: authmethod_lookup publickey debug3: remaining preferred: keyboard-interactive,password debug3: authmethod_is_enabled publickey debug1: Next authentication method: publickey debug1: Offering public key: /root/.ssh/id_rsa RSA SHA256:qvRNyydFqnVmaBYZkH3+GHFpnPZt5R1YmenSJfpI2KM debug3: send packet: type 50 debug2: we sent a publickey packet, wait for reply debug3: receive packet: type 51 debug1: Authentications that can continue: publickey,password debug1: Trying private key: /root/.ssh/id_dsa debug3: no such identity: /root/.ssh/id_dsa: No such file or directory debug1: Trying private key: /root/.ssh/id_ecdsa debug3: no such identity: /root/.ssh/id_ecdsa: No such file or directory debug1: Trying private key: /root/.ssh/id_ecdsa_sk debug3: no such identity: /root/.ssh/id_ecdsa_sk: No such file or directory debug1: Trying private key: /root/.ssh/id_ed25519 debug3: no such identity: /root/.ssh/id_ed25519: No such file or directory debug1: Trying private key: /root/.ssh/id_ed25519_sk debug3: no such identity: /root/.ssh/id_ed25519_sk: No such file or directory debug1: Trying private key: /root/.ssh/id_xmss debug3: no such identity: /root/.ssh/id_xmss: No such file or directory debug2: we did not send a packet, disable method debug3: authmethod_lookup password debug3: remaining preferred: ,password debug3: authmethod_is_enabled password debug1: Next authentication method: password root@192.168.1.1's password: Quote
rustrict Posted November 10, 2020 Posted November 10, 2020 Пока я заметил, что вы переносили ключ не из той папки, которую проверяет ssh. Попробуйте: cat /root/.ssh/id_rsa.pub | ssh -p 222 root@192.168.1.1 "cat > /opt/etc/dropbear/authorized_keys && chmod 600 /opt/etc/dropbear/authorized_keys" 2 2 Quote
Michael_ich Posted November 10, 2020 Author Posted November 10, 2020 (edited) 13 minutes ago, rustrict said: Пока я заметил, что вы переносили ключ не из той папки, которую проверяет ssh. Попробуйте: cat /root/.ssh/id_rsa.pub | ssh -p 222 root@192.168.1.1 "cat > /opt/etc/dropbear/authorized_keys && chmod 600 /opt/etc/dropbear/authorized_keys" Решил переключится и попробовать по новой на малинкеssh -i /root/.ssh/id_rsa.pub -p '22' 'michael@192.168.1.11' -vvv Spoiler bash-5.0# ssh -i /root/.ssh/id_rsa.pub -p '22' 'michael@192.168.1.11' -vvv OpenSSH_8.3p1, OpenSSL 1.1.1g 21 Apr 2020 debug1: Reading configuration data /etc/ssh/ssh_config debug2: resolve_canonicalize: hostname 192.168.1.11 is address debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug2: ssh_connect_direct debug1: Connecting to 192.168.1.11 [192.168.1.11] port 22. debug1: Connection established. debug1: identity file /root/.ssh/id_rsa.pub type 0 debug1: identity file /root/.ssh/id_rsa.pub-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.3 debug1: Remote protocol version 2.0, remote software version OpenSSH_7.9p1 Raspbian-10+deb10u2 debug1: match: OpenSSH_7.9p1 Raspbian-10+deb10u2 pat OpenSSH* compat 0x04000000 debug2: fd 3 setting O_NONBLOCK debug1: Authenticating to 192.168.1.11:22 as 'michael' debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:1 debug3: load_hostkeys: loaded 1 keys from 192.168.1.11 debug3: order_hostkeyalgs: prefer hostkeyalgs: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521 debug3: send packet: type 20 debug1: SSH2_MSG_KEXINIT sent debug3: receive packet: type 20 debug1: SSH2_MSG_KEXINIT received debug2: local client KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c debug2: host key algorithms: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,sk-ssh-ed25519@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: compression ctos: none,zlib@openssh.com,zlib debug2: compression stoc: none,zlib@openssh.com,zlib debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug2: peer server KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1 debug2: host key algorithms: rsa-sha2-512,rsa-sha2-256,ssh-rsa,ecdsa-sha2-nistp256,ssh-ed25519 debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: compression ctos: none,zlib@openssh.com debug2: compression stoc: none,zlib@openssh.com debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug3: send packet: type 30 debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug3: receive packet: type 31 debug1: Server host key: ecdsa-sha2-nistp256 SHA256:sJS7Q7IEyA1G/1atSR5dklAFo7aGfcpUE3dtQwS1Yc4 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:1 debug3: load_hostkeys: loaded 1 keys from 192.168.1.11 debug1: Host '192.168.1.11' is known and matches the ECDSA host key. debug1: Found key in /root/.ssh/known_hosts:1 debug3: send packet: type 21 debug2: set_newkeys: mode 1 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug3: receive packet: type 21 debug1: SSH2_MSG_NEWKEYS received debug2: set_newkeys: mode 0 debug1: rekey in after 134217728 blocks debug1: Will attempt key: /root/.ssh/id_rsa.pub RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k explicit debug2: pubkey_prepare: done debug3: send packet: type 5 debug3: receive packet: type 7 debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521> debug3: receive packet: type 6 debug2: service_accept: ssh-userauth debug1: SSH2_MSG_SERVICE_ACCEPT received debug3: send packet: type 50 debug3: receive packet: type 51 debug1: Authentications that can continue: publickey,password debug3: start over, passed a different list publickey,password debug3: preferred publickey,keyboard-interactive,password debug3: authmethod_lookup publickey debug3: remaining preferred: keyboard-interactive,password debug3: authmethod_is_enabled publickey debug1: Next authentication method: publickey debug1: Offering public key: /root/.ssh/id_rsa.pub RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k explicit debug3: send packet: type 50 debug2: we sent a publickey packet, wait for reply debug3: receive packet: type 60 debug1: Server accepts key: /root/.ssh/id_rsa.pub RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k explicit debug3: sign_and_send_pubkey: RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k debug3: sign_and_send_pubkey: signing using rsa-sha2-512 SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4kLoad key "/root/.ssh/id_rsa.pub": invalid format debug2: we did not send a packet, disable method debug3: authmethod_lookup password debug3: remaining preferred: ,password debug3: authmethod_is_enabled password debug1: Next authentication method: password michael@192.168.1.11's password: Что может быть с форматом не знаю Генерил просто ssh-keygen без параметров bash-5.0# cat id_rsa.pub ssh-rsa AA.............................0= root@homeassistant Edited November 10, 2020 by Michael_ich Quote
Michael_ich Posted November 10, 2020 Author Posted November 10, 2020 (edited) Вот так на малинке заработало bash-5.0# ssh -p '22' 'michael@192.168.1.11' pwd /home/michael bash-5.0# А на интернет центре нет bash-5.0# ssh -p '222' 'root@192.168.1.1' pwd root@192.168.1.1's password: Edited November 10, 2020 by Michael_ich Quote
rustrict Posted November 10, 2020 Posted November 10, 2020 3 минуты назад, Michael_ich сказал: ssh -i /root/.ssh/id_rsa.pub -p '22' 'michael@192.168.1.11' -vvv Здесь надо или без -i вообще, или -i /root/.ssh/id_rsa. Давайте все-таки вернемся к Entware. Появился ли доступ по ключу после моей команды выше? Если нет, то покажите еще права на папки: На клиентском устройстве ls -la /root/.ssh На роутере ls -la /opt/etc/dropbear 1 Quote
Michael_ich Posted November 10, 2020 Author Posted November 10, 2020 (edited) 17 minutes ago, rustrict said: Здесь надо или без -i вообще, или -i /root/.ssh/id_rsa. Давайте все-таки вернемся к Entware. Появился ли доступ по ключу после моей команды выше? Если нет, то покажите еще права на папки: На клиентском устройстве ls -la /root/.ssh На роутере ls -la /opt/etc/dropbear После команды выше не появился. Spoiler bash-5.0# ls -la /root/.ssh total 24 drwx------ 2 root root 4096 Nov 10 15:02 . drwx------ 1 root root 4096 Nov 10 15:02 .. -rw------- 1 root root 2602 Nov 10 15:02 id_rsa -rw------- 1 root root 572 Nov 10 15:02 id_rsa.pub -rw-r--r-- 1 root root 353 Nov 10 15:17 known_hosts Spoiler ~ # ls -la /opt/etc/dropbear drwxrwxr-x 1 root HA 4096 Nov 10 15:21 . drwxrwxr-x 1 root HA 4096 Nov 9 17:25 .. -rw------- 1 root HA 572 Nov 10 15:21 authorized_keys -rwxrwxr-x 1 root HA 140 Oct 12 18:16 dropbear_ecdsa_host_key -rwxrwxr-x 1 root HA 83 Oct 12 18:16 dropbear_ed25519_host_key -rwxrwxr-x 1 root HA 805 Oct 12 18:16 dropbear_rsa_host_key log Spoiler bash-5.0# ssh -p '222' 'root@192.168.1.1' -vvv OpenSSH_8.3p1, OpenSSL 1.1.1g 21 Apr 2020 debug1: Reading configuration data /etc/ssh/ssh_config debug2: resolve_canonicalize: hostname 192.168.1.1 is address debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug2: ssh_connect_direct debug1: Connecting to 192.168.1.1 [192.168.1.1] port 222. debug1: Connection established. debug1: identity file /root/.ssh/id_rsa type 0 debug1: identity file /root/.ssh/id_rsa-cert type -1 debug1: identity file /root/.ssh/id_dsa type -1 debug1: identity file /root/.ssh/id_dsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa type -1 debug1: identity file /root/.ssh/id_ecdsa-cert type -1 debug1: identity file /root/.ssh/id_ecdsa_sk type -1 debug1: identity file /root/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /root/.ssh/id_ed25519 type -1 debug1: identity file /root/.ssh/id_ed25519-cert type -1 debug1: identity file /root/.ssh/id_ed25519_sk type -1 debug1: identity file /root/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /root/.ssh/id_xmss type -1 debug1: identity file /root/.ssh/id_xmss-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.3 debug1: Remote protocol version 2.0, remote software version dropbear debug1: no match: dropbear debug2: fd 3 setting O_NONBLOCK debug1: Authenticating to 192.168.1.1:222 as 'root' debug3: put_host_port: [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:2 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug3: order_hostkeyalgs: prefer hostkeyalgs: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521 debug3: send packet: type 20 debug1: SSH2_MSG_KEXINIT sent debug3: receive packet: type 20 debug1: SSH2_MSG_KEXINIT received debug2: local client KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c debug2: host key algorithms: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,ssh-ed25519,sk-ssh-ed25519@openssh.com,rsa-sha2-512,rsa-sha2-256,ssh-rsa debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 debug2: compression ctos: none,zlib@openssh.com,zlib debug2: compression stoc: none,zlib@openssh.com,zlib debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug2: peer server KEXINIT proposal debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,kexguess2@matt.ucc.asn.au debug2: host key algorithms: ssh-ed25519,ecdsa-sha2-nistp256,rsa-sha2-256,ssh-rsa debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes256-ctr debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes256-ctr debug2: MACs ctos: hmac-sha1,hmac-sha2-256 debug2: MACs stoc: hmac-sha1,hmac-sha2-256 debug2: compression ctos: none debug2: compression stoc: none debug2: languages ctos: debug2: languages stoc: debug2: first_kex_follows 0 debug2: reserved 0 debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ecdsa-sha2-nistp256 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug3: send packet: type 30 debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug3: receive packet: type 31 debug1: Server host key: ecdsa-sha2-nistp256 SHA256:9BWRfXLc3Nkgef3/ZH1AjLxYkPYXXGpvWSlXQnOhFHU debug3: put_host_port: [192.168.1.1]:222 debug3: put_host_port: [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:2 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug3: hostkeys_foreach: reading file "/root/.ssh/known_hosts" debug3: record_hostkey: found key type ECDSA in file /root/.ssh/known_hosts:2 debug3: load_hostkeys: loaded 1 keys from [192.168.1.1]:222 debug1: Host '[192.168.1.1]:222' is known and matches the ECDSA host key. debug1: Found key in /root/.ssh/known_hosts:2 debug3: send packet: type 21 debug2: set_newkeys: mode 1 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug3: receive packet: type 21 debug1: SSH2_MSG_NEWKEYS received debug2: set_newkeys: mode 0 debug1: rekey in after 134217728 blocks debug1: Will attempt key: /root/.ssh/id_rsa RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k debug1: Will attempt key: /root/.ssh/id_dsa debug1: Will attempt key: /root/.ssh/id_ecdsa debug1: Will attempt key: /root/.ssh/id_ecdsa_sk debug1: Will attempt key: /root/.ssh/id_ed25519 debug1: Will attempt key: /root/.ssh/id_ed25519_sk debug1: Will attempt key: /root/.ssh/id_xmss debug2: pubkey_prepare: done debug3: send packet: type 5 debug3: receive packet: type 7 debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,rsa-sha2-256,ssh-rsa> debug3: receive packet: type 6 debug2: service_accept: ssh-userauth debug1: SSH2_MSG_SERVICE_ACCEPT received debug3: send packet: type 50 debug3: receive packet: type 51 debug1: Authentications that can continue: publickey,password debug3: start over, passed a different list publickey,password debug3: preferred publickey,keyboard-interactive,password debug3: authmethod_lookup publickey debug3: remaining preferred: keyboard-interactive,password debug3: authmethod_is_enabled publickey debug1: Next authentication method: publickey debug1: Offering public key: /root/.ssh/id_rsa RSA SHA256:am2b3n+E46I/+9MBE1qRgbJJAL1NH3AKZ3P0EvTDS4k debug3: send packet: type 50 debug2: we sent a publickey packet, wait for reply debug3: receive packet: type 51 debug1: Authentications that can continue: publickey,password debug1: Trying private key: /root/.ssh/id_dsa debug3: no such identity: /root/.ssh/id_dsa: No such file or directory debug1: Trying private key: /root/.ssh/id_ecdsa debug3: no such identity: /root/.ssh/id_ecdsa: No such file or directory debug1: Trying private key: /root/.ssh/id_ecdsa_sk debug3: no such identity: /root/.ssh/id_ecdsa_sk: No such file or directory debug1: Trying private key: /root/.ssh/id_ed25519 debug3: no such identity: /root/.ssh/id_ed25519: No such file or directory debug1: Trying private key: /root/.ssh/id_ed25519_sk debug3: no such identity: /root/.ssh/id_ed25519_sk: No such file or directory debug1: Trying private key: /root/.ssh/id_xmss debug3: no such identity: /root/.ssh/id_xmss: No such file or directory debug2: we did not send a packet, disable method debug3: authmethod_lookup password debug3: remaining preferred: ,password debug3: authmethod_is_enabled password debug1: Next authentication method: password root@192.168.1.1's password: Edited November 10, 2020 by Michael_ich Quote
Rage Steel Posted May 10, 2024 Posted May 10, 2024 Вчера взялся за настройку свежекупленного Keenetic — у меня всё сработало после того как файл authorized_keys передвинул из ~/.ssh/ в /opt/etc/dropbear 3 Quote
Chunga_ch4nga Posted March 22, 2025 Posted March 22, 2025 Сегодня также настраивал роутер Keenetic, но даже после переноса файла authorized_keys в /opt/etc/dropbear подключение без пароля не сработало. Затем в логах роутера увидел ошибку "/opt/etc/dropbear must be owned by user or root, and not writable by group or others". Пришлось для этой папки и всего содержимого проставить права через chmod 755. После перезапуска dropbear ("./opt/etc/init.d/S(xx)dropbear restart") все заработало. 1 Quote
Сергей А. Posted March 19 Posted March 19 Здравствуйте Может кто-нибьудь запилить инструкцию как сделать авторизацию без пароля на кинетике? А то я попытался, но у меня не получилось. Понию, что нужно посмотреть логи и проверить Цитата "Я вам в другой теме предложил посмотреть лог подключения. Проверьте, например, что в ряду PreferredAuthentications publickey стоит впереди password:" но я не понимаю где проверить эти настройки и как и где включить уровень логирования DEBUG3 и где потом смотреть результаты. Или может уже есть где нормальная, полная инструкцитя? Но я нашёл только эту тему Quote
RangerKRS Posted March 27 Posted March 27 На винде если: Правая кнопка по меню "Пуск" -> Терминал В терминале команды: ssh-keygen cat ~/.ssh/id_edXXXX.pub | ssh -p 222 root@192.168.1.1 "cat > /opt/etc/dropbear/authorized_keys && chmod 600 /opt/etc/dropbear/authorized_keys" где ХХХХ - ваши цифры, смотреть в c:\Users\Имя_пользователя\.ssh\ Quote
Сергей А. Posted March 28 Posted March 28 (edited) Благодарю! 1 - Пара вопросов - предполагается, что вторая строка (которая с кат и чмодом) - уже не в виндовом терминале а в линекс среде? На пример в самом кинетике? Зачем делать ssh -p 222 ... если мы уже не в нём?!? Видел кучу примеров (в том числе и на инглише) и везде делается так!!! Я сделал просто копированием - и оно сработало. Потом перестанет работать или как это понимать? 2 - ключ нужно именно генерировать новый? Нельзя взять имеющийся в том каталоге кинетика id_dropbear? У меня этот вариант не сработал (в прошлый раз) и я решил что что-то не так сделал. Сейчас сгенерил новый - и заработало (либо в прошлый раз я всё же что-то сделал не то, но не понял что именно) Edited March 28 by Сергей А. Quote
bzzztomas77 Posted March 28 Posted March 28 Quote 2 - ключ нужно именно генерировать новый? публичный ключ (новый или существующи) берется с клиента $ ls -l ~/.ssh/*.pub -rw-r--r-- 1 alexey alexey 611 Nov 12 2024 /home/alexey/.ssh/id_dsa.pub -rw-r--r-- 1 alexey alexey 183 Nov 12 2024 /home/alexey/.ssh/id_ecdsa.pub -rw-r--r--. 1 alexey alexey 103 Jul 31 2023 /home/alexey/.ssh/id_ed25519.pub -rw-r--r-- 1 alexey alexey 575 Apr 18 2025 /home/alexey/.ssh/id_rsa.pub и добавляется в серверый файл: sp ~$ ls -l /opt/root/.ssh/ -rw-r--r-- 1 root root 188 Aug 18 2025 known_hosts на клиенте ssh можно запустить с ключом -v -- будет показывать какие ключи пробует Quote
Сергей А. Posted March 29 Posted March 29 У меня на кинетике в ~/.ssh/*.pub дополнительно присутствовала пара файлов id_dropbear.* с одинаковой датой и временем создания. Мне понравилось имя - поэтому его и взял. Я взял публичный для авторизации а из приватного putty gen`ом сконвертировал ключ для сессии putty Сразу скажу - что да, у файлов id_dropbear.* была одинаковая пара имён и одинаковая дата и время - но я не помню от куда они там и хз какого они формата/типа (только сейчас подумал - когда писал это) - но реально - я хз что за пара файлов. Но - если бы это была реальная пара ключей поддерживаемого кинетиком типа/формата - с ними тоже должно было бы сработать? Я пытаюсь понять, какие ошибки мог допустить когда сам экспериментировал. (Сейчас думаю что главная ошибка - взял хз какой ключ хз какого формата/типа) Quote
Nate Adams Posted July 20 Posted July 20 (edited) В общем, много разных советов читал, но нормальной инструкции так и не нашёл, так что вот вам моя версия с успешным подключением по ключу. Подключение через порт DropBear (предустановленный пакет Entware) - не путайте с параметрами SSH, настраиваемыми на самом роутере. При подключении напрямую к DropBear вы попадаете в Entware минуя cli роутера (не нужно будет писать `exec sh`). Может потребоваться настраивать разрешение в фаерволе самого роутера (через веб-морду). Настройки для ROOT (пароль должен быть задан при первоначальной настройке Entware)! Для Windows-пользователей расположение config-файла SSH и ключи по умолчанию в папке пользователя: C:\Users\<USERNAME>\.ssh ( %userprofile%\.ssh ) Настройка входа по SSH-ключу в Entware Dropbear на Keenetic 1. Создать SSH-ключ на компьютере Если ключа ещё нет: ssh-keygen -t ed25519 По умолчанию будут созданы: ~/.ssh/id_ed25519 ~/.ssh/id_ed25519.pub id_ed25519 — приватный ключ, его никому не передавать; id_ed25519.pub — публичный ключ, его нужно добавить на роутер. 2. Определить домашний каталог root в Entware Подключиться к Entware Dropbear по паролю и выполнить: echo "$HOME" grep '^root:' /opt/etc/passwd /etc/passwd 2>/dev/null Обычно для Entware: HOME=/opt/root 3. Создать каталог для ключей На роутере: mkdir -p /opt/root/.ssh chmod 700 /opt/root/.ssh Добавить содержимое публичного ключа в файл: nano /opt/root/.ssh/authorized_keys Вставить одну строку вида: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... user@computer После сохранения: chmod 600 /opt/root/.ssh/authorized_keys chown -R root:root /opt/root/.ssh Проверить: ls -ld /opt/root /opt/root/.ssh ls -l /opt/root/.ssh/authorized_keys Нормальные права: drwxr-xr-x /opt/root drwx------ /opt/root/.ssh -rw------- /opt/root/.ssh/authorized_keys 4. Проверить вход с явным указанием ключа На компьютере: ssh -i ~/.ssh/id_ed25519 -p 222 root@ROUTER_IP Для проверки без перехода к паролю: ssh -o BatchMode=yes -i ~/.ssh/id_ed25519 -p 222 root@ROUTER_IP Если вход прошёл — настройка готова. 5. Если Dropbear всё равно требует пароль Запустить временный Dropbear на другом порту, явно указав каталог с authorized_keys: /opt/sbin/dropbear \ -F \ -E \ -p 223 \ -P /tmp/dropbear-test.pid \ -D /opt/root/.ssh Из другого окна проверить: ssh -o BatchMode=yes -i ~/.ssh/id_ed25519 -p 223 root@ROUTER_IP Если с параметром -D ключ заработал, значит установленный Dropbear по умолчанию ищет authorized_keys не в домашнем каталоге пользователя. 6. Постоянно указать каталог authorized_keys Открыть конфигурацию: nano /opt/etc/config/dropbear.conf Добавить: AUTHORIZED_KEYS_DIR="/opt/root/.ssh" Пример полного файла: PORT=222 PIDFILE="/opt/var/run/dropbear.pid" AUTHORIZED_KEYS_DIR="/opt/root/.ssh" Открыть init-скрипт: nano /opt/etc/init.d/S51dropbear Найти функцию запуска: start() { $DROPBEAR -p $PORT -P $PIDFILE } Заменить на: start() { $DROPBEAR -p "$PORT" -P "$PIDFILE" -D "$AUTHORIZED_KEYS_DIR" } Перезапустить Dropbear: /opt/etc/init.d/S51dropbear restart Текущую SSH-сессию до проверки лучше не закрывать. Проверить из нового окна: ssh -o BatchMode=yes -i ~/.ssh/id_ed25519 -p 222 root@ROUTER_IP 7. Проверить параметры запущенного процесса На роутере: ps w | grep '[d]ropbear' У Entware Dropbear должна быть строка примерно такого вида: /opt/sbin/dropbear -p 222 -P /opt/var/run/dropbear.pid -D /opt/root/.ssh Также можно проверить слушающий порт: netstat -lntp | grep ':222' 8. Удобная запись в SSH config На компьютере можно добавить: Host my-router HostName 192.168.1.1 User root Port 222 IdentityFile ~/.ssh/id_ed25519 IdentitiesOnly yes После этого подключение выполняется одной командой: ssh my-router "my-router" можно заменить на любое удобное для вас название. HostName - указываете IP роутера (внутренний, если работаете в сети роутера / внешний, если подключаетесь извне и открыт доступ на фаерволе роутера) Диагностика Для подробного вывода клиента: ssh -vvv -i ~/.ssh/id_ed25519 -p 222 root@ROUTER_IP В исправном случае должны появиться строки: Offering public key Server accepts key Authenticated ... using "publickey" Если есть: Offering public key но нет: Server accepts key значит клиент ключ нашёл, но Dropbear его отвергает. Нужно проверять: путь к authorized_keys; параметр -D; права каталогов и файла; соответствие публичного ключа приватному; пользователя, под которым выполняется вход. Поиск файлов вида `id_ed25519-cert` и `id_ed25519-cert.pub` в отладочном выводе OpenSSH является нормальным. Клиент автоматически проверяет наличие SSH-сертификата рядом с обычным ключом; отсутствие этих файлов не мешает авторизации обычным ключом. Edited July 20 by Nate Adams Опечатки, плюс небольшое дополнение. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.