- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- ssh question
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 03:58 AM
05-10-2006 03:58 AM
ssh question
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:13 AM
05-10-2006 04:13 AM
Re: ssh question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:26 AM
05-10-2006 04:26 AM
Re: ssh question
you can use remsh command to run a commend line based task remotely.
http://docs.hp.com/en/B2355-90690/remsh.1.html
here is an example of remote command via ssh.
http://www.itc.virginia.edu/desktop/security/ssh.html
Regards,
Sung
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:31 AM
05-10-2006 04:31 AM
Re: ssh question
I want to be able to:
ssh
but not
ssh
the latter being a login to the machine
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:34 AM
05-10-2006 04:34 AM
Re: ssh question
I don't think it's possible, because ssh, scp and sftp all uses the same port(22).
I quess you don't want to use rcp/remsh because of the security risks.
Maybe you can check for a restricted shell, where you only allow scp, but don't know if it's possible.
Darrel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:40 AM
05-10-2006 04:40 AM
Re: ssh question
To use ssh as an equivalent to rexec or remsh you have to assign a working shell program like /usr/bin/sh to the user account. But you can edit the .profile and add:
cleanupExit() # Declare an exit routine
{
print "Bye!"
sleep 1
exit 0
}
print "Sorry! You may not login directly into this system!"
print "Press Return to Continue"
read
cleanupExit
Put the cleanupExit at top of .profile and the rest at the bottom. ssh will still work just fine as a remote shell command, but the user can not successfully login to the system.
The only problem with this approach is if you have password aging enabled. At some point the user will have to approach you to reset their password, even if you use certificates.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:44 AM
05-10-2006 04:44 AM
Re: ssh question
I've tested the following:
- Added the following to my .profile
echo " No shell Login allowed"
exit
I'm able to scp to the server and logged out when I try ssh
You can also add "trap" codes to the .profile.
Darrel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 04:44 AM
05-10-2006 04:44 AM
Re: ssh question
ssh hostname "command"
Please refer
http://unixhelp.ed.ac.uk/CGI/man-cgi?ssh+1
for some help.
Regards,
ninad
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 06:43 AM
05-10-2006 06:43 AM
Re: ssh question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 09:16 PM
05-10-2006 09:16 PM
Re: ssh question
Create a new rsa (or dsa) key pair
$ ssh-keygen -t rsa -b 1024 -N "" -f ~/.ssh/id_rsa_cmd
Edit the public key of the pair and place the commands you wish to be executed in the header.
$ vi ~/.ssh/id_rsa_cmd.pub
$ dd if=~/.ssh/id_rsa_cmd.pub bs=25 count=1 2>/dev/null;echo
command="hostname;uptime"
Distribute the public key to a remote ssh host where you want this command to be run on connect.
$ ssh saz@gouda 'cat >>.ssh/authorized_keys' < ~/.ssh/id_rsa_cmd.pub
Run a login with this key
$ ssh -i ~/.ssh/id_rsa_cmd saz@gouda
gouda
11:13am up 104 days, 23:35, 1 user, load average: 1.31, 1.47, 1.53
Connection to gouda closed.
To abbreviate the invocation you could edit
~/.ssh/config
on the SSH client and add a
Host entry
with
IdentityFile ~/.ssh/id_rsa_cmd
Then you can omit the -i switch.
See "man ssh_config" for details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 10:32 PM
05-10-2006 10:32 PM
Re: ssh question
http://www.oreilly.com/catalog/sshtdg/chapter/ch08.html
//Michael