Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revisionBoth sides next revision | ||
doku:vpn_ssh_access [2017/09/01 13:41] – [Generate ssh-key] ir | doku:vpn_ssh_access [2024/05/02 09:54] – [Security issues] adding link to man sshd jz | ||
---|---|---|---|
Line 8: | Line 8: | ||
Common ways of connecting are either the use of a VPN or a SSH gateway provided by the university. | Common ways of connecting are either the use of a VPN or a SSH gateway provided by the university. | ||
- | See also [[doku:vsc3quickstart|Login]], and [[doku: | + | See also [[pandoc:introduction-to-vsc: |
=== VPN services === | === VPN services === | ||
- | * University of Vienna: [[http:// | + | * University of Vienna: [[http:// |
- | * TU Vienna: [[http://www.zid.tuwien.ac.at/ | + | * TU Vienna: [[https://www.it.tuwien.ac.at/ |
* University of Innsbruck: [[http:// | * University of Innsbruck: [[http:// | ||
- | * University of Graz: [[http:// | + | * University of Graz: [[https:// |
- | * TU Graz: [[https://sso.tugraz.at/idp/Authn/GenericAuthn| Web Single Sign-On]] | + | * TU Graz: [[http://portal.tugraz.at/portal/page/portal/ |
=== SSH Gateway === | === SSH Gateway === | ||
- | Users can connect first to any linux machine within a university and then connect further to VSC. Some universities provide a dedicated SSH gateway (contact your local IT services if you don't know how to connect): | + | Users can connect first to any linux machine within a university and then connect further to VSC. Some universities provide a dedicated SSH gateway (contact your local IT services if you don't know how to connect). |
- | * TU Graz: [[https:// | + | |
====== Using SSH keys and SSH agent to connect to VSC ====== | ====== Using SSH keys and SSH agent to connect to VSC ====== | ||
Line 52: | Line 51: | ||
* written to '' | * written to '' | ||
- | ==== Connecting to VSC-2 or VSC-3 via ssh-key: ==== | + | ==== Connecting to VSC-4 or VSC-5 via ssh-key: ==== |
< | < | ||
- | ssh -p 27 < | + | ssh -p 27 < |
- | ssh -p 27 < | + | ssh -p 27 < |
</ | </ | ||
- | === Forwarding the ssh-agent over multiple servers | + | === Using a jump host === |
- | If the machine to which one wants to login is reachable only over one or several hops in between, the ssh-agent of the local machine can be forwarded to the machines in between using the '-A' | + | It is also possible to use SSH keys if the machine to which one wants to login is reachable only over one or several hops in between. To do this, use the command ''-J'' to specify |
< | < | ||
- | user@host: | + | user@host: |
</ | </ | ||
Line 69: | Line 68: | ||
< | < | ||
- | Host vsc3.vsc.ac.at | + | Host vsc5.vsc.ac.at |
Port 27 | Port 27 | ||
+ | User vsc_username | ||
# ForwardAgent yes | # ForwardAgent yes | ||
IdentityFile id_rsa | IdentityFile id_rsa | ||
IdentitiesOnly yes | IdentitiesOnly yes | ||
# ForwardX11 yes | # ForwardX11 yes | ||
+ | </ | ||
+ | |||
+ | === Using a jump host === | ||
+ | A configuration for automatically using a jump host could look like this: | ||
+ | |||
+ | < | ||
+ | Host vsc5.vsc.ac.at vsc5 | ||
+ | User vsc_username | ||
+ | ProxyJump login.univie.ac.at | ||
+ | |||
+ | Host login.univie.ac.at | ||
+ | User uni_username | ||
</ | </ | ||
Line 80: | Line 92: | ||
* In theory it would be possible to create an ssh key without passphrase. However, the possession of this key would allow anyone from anywhere to open a connection. | * In theory it would be possible to create an ssh key without passphrase. However, the possession of this key would allow anyone from anywhere to open a connection. | ||
* Forwarding the ssh key as a standard procedure, e.g. by aliasing the ' | * Forwarding the ssh key as a standard procedure, e.g. by aliasing the ' | ||
- | * One of the worst security issues concerning ssh keys would be to create a passphrase-less ssh-key and copy the public key directly to the ' | + | * One of the worst security issues concerning ssh keys would be to create a passphrase-less ssh-key and copy the public key directly to the ' |