[{"data":1,"prerenderedAt":1154},["ShallowReactive",2],{"i-lucide:menu":3,"i-lucide:arrow-up-right":8,"i-lucide:moon":10,"i-lucide:sun":12,"i-lucide:rss":14,"i-simple-icons:github":16,"i-simple-icons:linkedin":18,"post-\u002F2016\u002Fsecuring-ssh-keys":21,"surround-\u002F2016\u002Fsecuring-ssh-keys":617,"i-lucide:arrow-left":626,"i-lucide:arrow-right":628,"gist-25c82171f49aa09390f3a22cf29254db":630},{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":7},0,24,false,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":9},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M7 7h10v10M7 17L17 7\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":11},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":13},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"4\"\u002F>\u003Cpath d=\"M12 2v2m0 16v2M4.93 4.93l1.41 1.41m11.32 11.32l1.41 1.41M2 12h2m16 0h2M6.34 17.66l-1.41 1.41M19.07 4.93l-1.41 1.41\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":15},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M4 11a9 9 0 0 1 9 9M4 4a16 16 0 0 1 16 16\"\u002F>\u003Ccircle cx=\"5\" cy=\"19\" r=\"1\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":17},"\u003Cpath fill=\"currentColor\" d=\"M12 .297c-6.63 0-12 5.373-12 12c0 5.303 3.438 9.8 8.205 11.385c.6.113.82-.258.82-.577c0-.285-.01-1.04-.015-2.04c-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729c1.205.084 1.838 1.236 1.838 1.236c1.07 1.835 2.809 1.305 3.495.998c.108-.776.417-1.305.76-1.605c-2.665-.3-5.466-1.332-5.466-5.93c0-1.31.465-2.38 1.235-3.22c-.135-.303-.54-1.523.105-3.176c0 0 1.005-.322 3.3 1.23c.96-.267 1.98-.399 3-.405c1.02.006 2.04.138 3 .405c2.28-1.552 3.285-1.23 3.285-1.23c.645 1.653.24 2.873.12 3.176c.765.84 1.23 1.91 1.23 3.22c0 4.61-2.805 5.625-5.475 5.92c.42.36.81 1.096.81 2.22c0 1.606-.015 2.896-.015 3.286c0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":19,"hidden":20},"\u003Cpath fill=\"currentColor\" d=\"M20.447 20.452h-3.554v-5.569c0-1.328-.027-3.037-1.852-3.037c-1.853 0-2.136 1.445-2.136 2.939v5.667H9.351V9h3.414v1.561h.046c.477-.9 1.637-1.85 3.37-1.85c3.601 0 4.267 2.37 4.267 5.455v6.286zM5.337 7.433a2.06 2.06 0 0 1-2.063-2.065a2.064 2.064 0 1 1 2.063 2.065m1.782 13.019H3.555V9h3.564zM22.225 0H1.771C.792 0 0 .774 0 1.729v20.542C0 23.227.792 24 1.771 24h20.451C23.2 24 24 23.227 24 22.271V1.729C24 .774 23.2 0 22.222 0z\"\u002F>",true,{"id":22,"title":23,"body":24,"category":605,"comments":606,"date":607,"description":30,"excerpt":606,"extension":608,"image":606,"meta":609,"navigation":20,"path":610,"readingTime":611,"seo":612,"stem":613,"subtitle":614,"tags":606,"wordCount":615,"__hash__":616},"posts\u002F2016\u002Fsecuring-ssh-keys.md","Securing SSH Keys",{"type":25,"value":26,"toc":596},"minimark",[27,31,34,39,55,64,68,71,84,87,91,94,109,112,115,120,136,144,151,168,181,185,188,207,210,251,268,272,279,282,299,303,308,323,332,348,356,371,375,381,387,390,403,409,415,428,433,438,444,450,456,459,465,479,485,494,498,502,514,520,523,527,530,540,565,568,574,578,587,592],[28,29,30],"p",{},"Recently, due to some changes at the workplace, I've been re-evaluating the practices I use to secure my secrets - particularly, my access credentials and specifically, my SSH key pair.",[28,32,33],{},"This post lists the changes I made to stay more secure and sleep better at night. I will narrow the focus to protecting SSH keys and will not talk about other considerations such as BIOS passwords and encrypted OS hard-drives.",[35,36,38],"h1",{"id":37},"the-situation-before","The Situation Before",[28,40,41,42,46,47,50,51,54],{},"I had a password-less 2048-bit RSA key in ",[43,44,45],"code",{},"~\u002F.ssh\u002Fid_rsa",". It was quick to use and convenient, but left me wide-open to exploitation by whoever had read access to my ",[43,48,49],{},".ssh"," directory - such as any program running under my user or ",[43,52,53],{},"root",".",[28,56,57,58,63],{},"Adding a password to the key encrypts it, however the drawback is that you need to enter a password every time the key is used - which, depending on your work, might be ~40 times a day (",[59,60,62],"a",{"href":61},"#note-1","1","), so I had not done so.",[35,65,67],{"id":66},"things-to-change","Things To Change",[28,69,70],{},"After consulting my colleagues, in-house security practices and a bit of online research, I decided to:",[72,73,74,78,81],"ul",{},[75,76,77],"li",{},"generate a new key with improved security using 256-bit ECDSA, not 2048-bit RSA",[75,79,80],{},"password-protect the private key",[75,82,83],{},"store the key on an encrypted USB drive and load it to memory for use",[28,85,86],{},"This would protect the key with a password (something I know) and store it externally (something I own), effectively requiring 2-factor authentication before the key can be used.",[35,88,90],{"id":89},"creating-the-encrypted-usb-drive","Creating The Encrypted USB Drive",[28,92,93],{},"Why store your SSH key on a USB stick? Think about it: what happens, when...",[72,95,96,99,106],{},[75,97,98],{},"your work PC is not disk-encrypted and I (the janitor) have physical access to your machine after-hours?",[75,100,101,102,105],{},"you run my open-source application that, by the way, e-mails me the contents of your ",[43,103,104],{},"~\u002F.ssh"," folder?",[75,107,108],{},"you get infected with ransomware?",[28,110,111],{},"All of these cases (and more) are examples on how someone might get access to the files on your HDD. Storing the key on external media (and loading it in-memory, then dismounting) removes this problem: the key is loaded into memory once, then removed from the system.",[28,113,114],{},"Obviously, the thumb-drive itself needs to be encrypted to protect against theft or loss.",[116,117,119],"h2",{"id":118},"encrypting-the-drive","Encrypting the Drive",[28,121,122,123,129,130,135],{},"I downloaded and installed ",[59,124,128],{"href":125,"rel":126},"https:\u002F\u002Fveracrypt.codeplex.com",[127],"nofollow","VeraCrypt",". It's a successor to ",[59,131,134],{"href":132,"rel":133},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTrueCrypt",[127],"TrueCrypt"," and (so far) looks the best alternative to the original.",[28,137,138,139,54],{},"Creating an encrypted USB drive with VeraCrypt is relatively straightforward - instructions (with pictures) can be ",[59,140,143],{"href":141,"rel":142},"https:\u002F\u002Fwww.deepdotweb.com\u002F2015\u002F02\u002F09\u002Fveracrypt-tutorial-how-to-encrypt-usb-drive",[127],"found here",[28,145,146],{},[147,148],"img",{"alt":149,"src":150},"Creating the volume","\u002Fcontent\u002F2016\u002F04\u002Fssh\u002Fcreate-volume.png",[28,152,153,154,157,158,163,164,167],{},"I also needed a new password for the USB encryption - something easy to remember, but difficult enough to brute force. Techniques like ",[43,155,156],{},"CatRanOverRoad"," (concatenating dictionary words together) or using ",[59,159,162],{"href":160,"rel":161},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FLeet",[127],"Leet","-speak (",[43,165,166],{},"p@$$word",") are not secure.",[28,169,170,171,176,177,180],{},"The ",[59,172,175],{"href":173,"rel":174},"https:\u002F\u002Fwww.schneier.com\u002Fblog\u002Farchives\u002F2014\u002F03\u002Fchoosing_secure_1.html",[127],"Bruce Schneier scheme"," offers an easy-to remember way for generating a new, long, memorable and (looking at it) completely gibberish password - it looked something like ",[43,178,179],{},"WIw7,mstmsr! iTt.",". It has mixed case, numbers and symbols in addition to being quite long and not a dictionary-word or a name.",[35,182,184],{"id":183},"creating-the-new-ssh-key","Creating the New SSH Key",[28,186,187],{},"My previous key was a password-less 2048-bit RSA key. I wanted to add a password and upgrade the security to RSA 4096 bits.",[28,189,190,195,196,195,201,206],{},[59,191,194],{"href":192,"rel":193},"https:\u002F\u002Fblog.cloudflare.com\u002Fecdsa-the-digital-signature-algorithm-of-a-better-internet",[127],"After"," ",[59,197,200],{"href":198,"rel":199},"http:\u002F\u002Fmartin.kleppmann.com\u002F2013\u002F05\u002F24\u002Fimproving-security-of-ssh-private-keys.html",[127],"some",[59,202,205],{"href":203,"rel":204},"http:\u002F\u002Fwww.tedunangst.com\u002Fflak\u002Fpost\u002Fnew-openssh-key-format-and-bcrypt-pbkdf",[127],"research"," about SSH key algorithm security I decided to switch over from RSA to a new an improved algorithm, ECDSA.",[28,208,209],{},"The following command generates a SSH key using ECDSA with 64 iterations (the default is 16) and saves it to the specified file.",[211,212,217],"pre",{"className":213,"code":214,"language":215,"meta":216,"style":216},"language-bash shiki shiki-themes github-light github-dark","$ ssh-keygen -t ed25519 -a 64 -f \u002Fmedia\u002Fveracrypt1\u002Fid_ed25519\n","bash","",[43,218,219],{"__ignoreMap":216},[220,221,224,228,232,236,239,242,245,248],"span",{"class":222,"line":223},"line",1,[220,225,227],{"class":226},"sScJk","$",[220,229,231],{"class":230},"sZZnC"," ssh-keygen",[220,233,235],{"class":234},"sj4cs"," -t",[220,237,238],{"class":230}," ed25519",[220,240,241],{"class":234}," -a",[220,243,244],{"class":234}," 64",[220,246,247],{"class":234}," -f",[220,249,250],{"class":230}," \u002Fmedia\u002Fveracrypt1\u002Fid_ed25519\n",[28,252,253,254,257,258,262,263,267],{},"ECDSA keys are not supported on older OpenSSH servers (older than ",[43,255,256],{},"5.7","), but this was not a problem for me (",[59,259,261],{"href":260},"#note-2","2","). When prompted for a password, I set one - again, a random-looking, long one - and saved the key directly to an encrypted volume (this does not save it to my \"plain\" HDD at all (",[59,264,266],{"href":265},"#note-3","3",")).",[35,269,271],{"id":270},"automating-key-use","Automating Key Use",[28,273,274,275,278],{},"The reason I generated my previous key without the password was convenience: I was under the impression that you need to enter the password for the key every time you use it. Now, I know better - a SSH utility, ",[43,276,277],{},"ssh-agent",", allows you to load the key into memory - once - and use it without re-prompting for a password.",[28,280,281],{},"This allows me to use the following workflow:",[72,283,284,287,293,296],{},[75,285,286],{},"every morning, I would arrive to work and unlock my PC (I usually log out of Ubuntu \u002F Unity for I have little faith in the lock screen)",[75,288,289,290,292],{},"I would then insert my encrypted USB stick, mount and unlock it and run ",[43,291,277],{}," to load the key from it into memory",[75,294,295],{},"after the key has been loaded I'm free to unplug the USB stick",[75,297,298],{},"they key will be purged from the memory automatically when the work-day ends",[116,300,302],{"id":301},"starting-ssh-agent","Starting ssh-agent",[28,304,305,307],{},[43,306,277],{}," might not be automatically started on login. If the following command prints a PID number, the agent is already running - everything should be fine.",[211,309,311],{"className":213,"code":310,"language":215,"meta":216,"style":216},"$ pidof ssh-agent\n",[43,312,313],{"__ignoreMap":216},[220,314,315,317,320],{"class":222,"line":223},[220,316,227],{"class":226},[220,318,319],{"class":230}," pidof",[220,321,322],{"class":230}," ssh-agent\n",[28,324,325,326,331],{},"I'm using Unity with Ubuntu 15.10; the agent was not auto-started. My shell environment is (oh-my) Zsh, which has a ",[59,327,330],{"href":328,"rel":329},"https:\u002F\u002Fstackoverflow.com\u002Fquestions\u002F21965611\u002Fhow-can-i-run-the-ssh-agent-auto-in-the-zsh-environment",[127],"plugin for starting ssh-agent"," on login.",[28,333,334,335,340,341,343,344,347],{},"Be aware of the ",[59,336,339],{"href":337,"rel":338},"http:\u002F\u002Frabexc.org\u002Fposts\u002Fpitfalls-of-ssh-agents",[127],"security pitfalls"," of running an agent. For example: the agent will stay running, even if you log out of Unity. To automatically stop ",[43,342,277],{}," when I log out, I created the file ",[43,345,346],{},"~\u002F.config\u002Fupstart\u002FdesktopClose.conf"," with the following content:",[211,349,354],{"className":350,"code":352,"language":353},[351],"language-text","description \"Desktop Close Task\"\nstart on session-end\ntask\nscript\n  killall ssh-agent\nend script\n","text",[43,355,352],{"__ignoreMap":216},[28,357,358,359,364,365,370],{},"A note about ",[59,360,363],{"href":361,"rel":362},"http:\u002F\u002Fwww.unixwiz.net\u002Ftechtips\u002Fssh-agent-forwarding.html",[127],"SSH Agent Forwarding",": I chose to leave it disabled as enabling it introduces ",[59,366,369],{"href":367,"rel":368},"https:\u002F\u002Fheipei.github.io\u002F2015\u002F02\u002F26\u002FSSH-Agent-Forwarding-considered-harmful",[127],"additional security risks",", especially in a shared-server environment.",[116,372,374],{"id":373},"loading-keys-automatically","Loading Keys Automatically",[28,376,377,378,380],{},"When ",[43,379,277],{}," starts, the keyring is empty - there are no loaded SSH keys.",[211,382,385],{"className":383,"code":384,"language":353},[351],"$ ssh-add -l\nThe agent has no identities.\n",[43,386,384],{"__ignoreMap":216},[28,388,389],{},"I want the system to load my key automatically when I enter the USB drive. This saves me ~30 seconds of typing time each day.",[28,391,392,393,398,399,402],{},"I created a new ",[59,394,397],{"href":395,"rel":396},"https:\u002F\u002Fwww.linux.com\u002Fnews\u002Fudev-introduction-device-management-modern-linux-system",[127],"udev"," rule, ",[43,400,401],{},"\u002Fetc\u002Fudev\u002Frules.d\u002F85-veracrypt.rules",":",[211,404,407],{"className":405,"code":406,"language":353},[351],"ACTION==\"add\", KERNEL==\"sd?\", ATTRS{serial}==\"AC220XXXXXXXXXXXXX\", RUN+=\"\u002Fusr\u002Flocal\u002Fbin\u002Fload-ssh-keys\"\n",[43,408,406],{"__ignoreMap":216},[28,410,411,412,54],{},"The rule will be loaded automatically when the machine starts. To load it manually, without restarting, one can run ",[43,413,414],{},"udevadm control --reload-rules",[28,416,417,418,420,421,424,425,54],{},"The new rule configures ",[43,419,397],{}," to run the ",[43,422,423],{},"load-ssh-keys"," program every time I insert my USB key. Note that the rule applies for only one specific key as it is bound by a serial number. To find out the serial number of the USB key, I ran ",[43,426,427],{},"udevadm info -a -n sdc",[429,430,432],"h3",{"id":431},"load-ssh-keyssh","load-ssh-keys.sh",[28,434,170,435,437],{},[43,436,423],{}," program works as follows. First, it prompts me for a password to decrypt the USB drive.",[28,439,440],{},[147,441],{"alt":442,"src":443},"Decrypting the volume","\u002Fcontent\u002F2016\u002F04\u002Fssh\u002Funlock-volume.png",[28,445,446,447,449],{},"If the password is correct, the volume is mounted in read-only mode. Next, the script tries to load the SSH key from the USB into ",[43,448,277],{}," (and prompts for the SSH key password).",[28,451,452],{},[147,453],{"alt":454,"src":455},"Unlocking the SSH key","\u002Fcontent\u002F2016\u002F04\u002Fssh\u002Funlock-key.png",[28,457,458],{},"When this succeeds, a success notification is displayed and the drive will be unmounted.",[28,460,461],{},[147,462],{"alt":463,"src":464},"OK notification","\u002Fcontent\u002F2016\u002F04\u002Fssh\u002Fok-notification.png",[28,466,467,468,471,472,475,476,478],{},"I use the ",[43,469,470],{},"-c"," flag with ",[43,473,474],{},"ssh-add",". This prompts me for confirmation every time ",[43,477,277],{}," wants to use my key. It's an additional manual step, but avoids issues where some other actor tries to access the agent without my knowledge.",[28,480,481],{},[147,482],{"alt":483,"src":484},"Key use confirmation","\u002Fcontent\u002F2016\u002F04\u002Fssh\u002Fkey-use-prompt.png",[28,486,487,488,493],{},"The script can be seen below (and on ",[59,489,492],{"href":490,"rel":491},"https:\u002F\u002Fgist.github.com\u002Fanroots\u002F25c82171f49aa09390f3a22cf29254db",[127],"GitHub",").",[495,496],"gist",{"id":497},"25c82171f49aa09390f3a22cf29254db",[35,499,501],{"id":500},"backups","Backups",[28,503,504,505,513],{},"Once the USB drive was \"ready\", I created backups of it following the ",[506,507,508],"em",{},[59,509,512],{"href":510,"rel":511},"http:\u002F\u002Fblog.trendmicro.com\u002Ftrendlabs-security-intelligence\u002Fworld-backup-day-the-3-2-1-rule",[127],"3-2-1"," rule:",[515,516,517],"blockquote",{},[28,518,519],{},"\"If you are backing something up, you should have at least three copies, in two different formats, with one of those copies off-site.\"",[28,521,522],{},"That way, even if I loose my keyring, I still have access to my private key.",[35,524,526],{"id":525},"conclusion","Conclusion",[28,528,529],{},"Learning more about SSH security and implementing the above-mentioned practices gives me more peace-of-mind. Previously, I had no protection whatsoever. Now, my key is protected with 2-factor authentication and literally in my pocket at all times, where it's safe*(r)* from foreign crackers.",[515,531,532],{},[28,533,534,535],{},"Security is something you know, something you have, and something you are. - ",[59,536,539],{"href":537,"rel":538},"http:\u002F\u002Ftammersaleh.com\u002Fposts\u002Fbuilding-an-encrypted-usb-drive-for-your-ssh-keys-in-os-x",[127],"Bruce Schneier",[28,541,542,195,546,549,550,555,556,558,559,564],{},[543,544,545],"strong",{},"Update",[506,547,548],{},"(2017-04-30)",": John Doe has ",[59,551,554],{"href":552,"rel":553},"https:\u002F\u002Fbitbucket.org\u002Fjohnniedoe\u002Fssh-loader",[127],"created his version of a script"," to automate loading keys from VeraCrypt to ",[43,557,277],{},". I have moved on from USB \u002F VeraCrypt and started using ",[59,560,563],{"href":561,"rel":562},"https:\u002F\u002Fwww.ftsafe.com\u002Fonlinestore\u002Fproduct?id=3",[127],"ePass"," as a key-storage. I hear it's possible to use a YubiKey for SSH key storage, as soon as I'm able, I shall look into that.",[566,567],"hr",{},[28,569,571,572,54],{"id":570},"note-1","(1): Encrypted private keys require the password on every use, but this can be circumvented by using ",[43,573,277],{},[28,575,577],{"id":576},"note-2","(2): ECDSA keys turned out to be problematic after all, due to some specific software we use that did not support them. I reverted to a 4096-bit RSA keys, which is still more secure than a 2048-bit one.",[28,579,581,582,586],{"id":580},"note-3","(3): Even if you save a file to your Desktop, then move it somewhere else, the file is not (actually) ",[59,583,585],{"href":584},"http:\u002F\u002Fwww.howtogeek.com\u002F125521\u002Fhtg-explains-why-deleted-files-can-be-recovered-and-how-you-can-prevent-it","immediately deleted"," an can be recovered from the disk.",[28,588,589],{},[506,590,591],{},"This article contains a lot of technical information. If you find a fault, please let me know.",[593,594,595],"style",{},"html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":216,"searchDepth":597,"depth":597,"links":598},2,[599,600,601],{"id":118,"depth":597,"text":119},{"id":301,"depth":597,"text":302},{"id":373,"depth":597,"text":374,"children":602},[603],{"id":431,"depth":604,"text":432},3,"Software Development",null,"2016-04-14","md",{},"\u002F2016\u002Fsecuring-ssh-keys","about 8 minutes",{"title":23,"description":30},"2016\u002Fsecuring-ssh-keys","Increasing key security by storing the private key on an encrypted USB drive",1480,"vi4gGf0eE3grtJsNxBPHNSv7xPUttUQer5QR_s4dm9A",[618,622],{"title":619,"path":620,"stem":621,"children":-1},"April Fools: Annoying Laughter Machine","\u002F2016\u002Fapril-fools-annoying-laughter-machine","2016\u002Fapril-fools-annoying-laughter-machine",{"title":623,"path":624,"stem":625,"children":-1},"Serving HTTPS Web Pages With Apache and Letsencrypt","\u002F2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt","2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":627},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m12 19l-7-7l7-7m7 7H5\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":629},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 12h14m-7-7l7 7l-7 7\"\u002F>",{"id":631,"title":632,"body":633,"createdAt":1146,"description":216,"extension":608,"files":1147,"gistId":497,"meta":1148,"navigation":20,"owner":1149,"path":1150,"seo":1151,"stem":1152,"url":490,"__hash__":1153},"gists\u002Fgists\u002F25c82171f49aa09390f3a22cf29254db.md","Load SSH key into ssh-agent from a veracrypt-encrypted drive when it's plugged in",{"type":25,"value":634,"toc":1144},[635,642,1141],[211,636,640],{"className":637,"code":638,"filename":639,"language":353,"meta":216},[351],"ACTION==\"add\", KERNEL==\"sd?\", ATTRS{serial}==\"SERIAL_NUMBER_OF_USB\", RUN+=\"\u002Fusr\u002Flocal\u002Fbin\u002Fload-ssh-keys\"\n","85-veracrypt.rules",[43,641,638],{"__ignoreMap":216},[211,643,645],{"className":213,"code":644,"filename":432,"language":215,"meta":216,"style":216},"#!\u002Fbin\u002Fbash\n\n# load-ssh-keys.sh\n# Author Ando Roots \u003Cando [at] sqroot [dot] eu> 2016\n# Licence: MIT\n# Requirements: VeraCrypt and `ssh-agent` installed, Ubuntu environment\n# Known problems: notify-send might not always work. All open nautilus windows will be killed.\n#\n# The following program is meant to be run by udev when a Veracrypt-encrypted USB drive\n# is inserted. The script mounts the drive, prompts for passwords and loads SSH keys into ss-agent.\n#\n# Customize as needed. More at https:\u002F\u002Fsqroot.eu\u002F2016\u002Fsecuring-ssh-keys\n#\n# The braces and '&' \"group\" the enclosed program into one logical unit and send it to the background.\n# This is done because the scripts run by udev should be very quick to exit, for it has a timeout value\n# (and this script calls for user input).\n{\n  # The DISPLAY variable tells VeraCrypt where to display the password prompt window\n  export DISPLAY=:0\n\n  # Change this to your UNIX username\n  LOGNAME=ando\n\n  # Xauthority is needed to be \"authorized\" to display something on the screen (password prompt)\n  export XAUTHORITY=\u002Fhome\u002F$LOGNAME\u002F.Xauthority\n\n  # This tells us the address to a ssh-agent socket (how one can connect to ssh-agent)\n  export SSH_AUTH_SOCK=`find \u002Ftmp -type s -name agent.\\* 2>\u002Fdev\u002Fnull`\n  \n  # DBUS address is needed to display notify-send messages\n  GNOME_PID=$(pgrep gnome-session)\n  export DBUS_SESSION_BUS_ADDRESS=$(grep -z DBUS_SESSION_BUS_ADDRESS \u002Fproc\u002F$GNOME_PID\u002Fenviron|cut -d= -f2-)\n\n  # Script execution, in order:\n  # \n  # - mount the encrypted drive (prompt for password)\n  # - close the Nautilus window that pops up for a new mounted device\n  # - add the SSH key to ssh-agent (prompt for password)\n  # - unmount the encrypted drive\n  # - display a notification that the key is loaded\n  # \n  # if any of the above steps failed, display a failure notification\n  veracrypt -m ro $DEVNAME \u002Fmedia\u002Fkeyring && \\\n  killall nautilus && \\\n  ssh-add -c -t 8h \u002Fmedia\u002Fkeyring\u002Fwork\u002Fid_rsa && \\\n  veracrypt -d $DEVNAME && \\\n  sudo -u $LOGNAME notify-send -i media-removable 'SSH keys loaded' \"`ssh-add -l`\" && \\\n  exit\n  sudo -u $LOGNAME notify-send -i emblem-unreadable 'Failed to load SSH keys' 'Investigate manually'\n} &\n",[43,646,647,653,658,663,669,675,681,687,693,699,705,710,716,721,727,733,739,746,752,768,773,779,790,795,800,813,818,824,864,870,876,896,939,944,950,956,962,968,974,980,986,991,997,1021,1034,1055,1068,1107,1113,1135],{"__ignoreMap":216},[220,648,649],{"class":222,"line":223},[220,650,652],{"class":651},"sJ8bj","#!\u002Fbin\u002Fbash\n",[220,654,655],{"class":222,"line":597},[220,656,657],{"emptyLinePlaceholder":20},"\n",[220,659,660],{"class":222,"line":604},[220,661,662],{"class":651},"# load-ssh-keys.sh\n",[220,664,666],{"class":222,"line":665},4,[220,667,668],{"class":651},"# Author Ando Roots \u003Cando [at] sqroot [dot] eu> 2016\n",[220,670,672],{"class":222,"line":671},5,[220,673,674],{"class":651},"# Licence: MIT\n",[220,676,678],{"class":222,"line":677},6,[220,679,680],{"class":651},"# Requirements: VeraCrypt and `ssh-agent` installed, Ubuntu environment\n",[220,682,684],{"class":222,"line":683},7,[220,685,686],{"class":651},"# Known problems: notify-send might not always work. All open nautilus windows will be killed.\n",[220,688,690],{"class":222,"line":689},8,[220,691,692],{"class":651},"#\n",[220,694,696],{"class":222,"line":695},9,[220,697,698],{"class":651},"# The following program is meant to be run by udev when a Veracrypt-encrypted USB drive\n",[220,700,702],{"class":222,"line":701},10,[220,703,704],{"class":651},"# is inserted. The script mounts the drive, prompts for passwords and loads SSH keys into ss-agent.\n",[220,706,708],{"class":222,"line":707},11,[220,709,692],{"class":651},[220,711,713],{"class":222,"line":712},12,[220,714,715],{"class":651},"# Customize as needed. More at https:\u002F\u002Fsqroot.eu\u002F2016\u002Fsecuring-ssh-keys\n",[220,717,719],{"class":222,"line":718},13,[220,720,692],{"class":651},[220,722,724],{"class":222,"line":723},14,[220,725,726],{"class":651},"# The braces and '&' \"group\" the enclosed program into one logical unit and send it to the background.\n",[220,728,730],{"class":222,"line":729},15,[220,731,732],{"class":651},"# This is done because the scripts run by udev should be very quick to exit, for it has a timeout value\n",[220,734,736],{"class":222,"line":735},16,[220,737,738],{"class":651},"# (and this script calls for user input).\n",[220,740,742],{"class":222,"line":741},17,[220,743,745],{"class":744},"sVt8B","{\n",[220,747,749],{"class":222,"line":748},18,[220,750,751],{"class":651},"  # The DISPLAY variable tells VeraCrypt where to display the password prompt window\n",[220,753,755,759,762,765],{"class":222,"line":754},19,[220,756,758],{"class":757},"szBVR","  export",[220,760,761],{"class":744}," DISPLAY",[220,763,764],{"class":757},"=",[220,766,767],{"class":744},":0\n",[220,769,771],{"class":222,"line":770},20,[220,772,657],{"emptyLinePlaceholder":20},[220,774,776],{"class":222,"line":775},21,[220,777,778],{"class":651},"  # Change this to your UNIX username\n",[220,780,782,785,787],{"class":222,"line":781},22,[220,783,784],{"class":744},"  LOGNAME",[220,786,764],{"class":757},[220,788,789],{"class":230},"ando\n",[220,791,793],{"class":222,"line":792},23,[220,794,657],{"emptyLinePlaceholder":20},[220,796,797],{"class":222,"line":5},[220,798,799],{"class":651},"  # Xauthority is needed to be \"authorized\" to display something on the screen (password prompt)\n",[220,801,803,805,808,810],{"class":222,"line":802},25,[220,804,758],{"class":757},[220,806,807],{"class":744}," XAUTHORITY",[220,809,764],{"class":757},[220,811,812],{"class":744},"\u002Fhome\u002F$LOGNAME\u002F.Xauthority\n",[220,814,816],{"class":222,"line":815},26,[220,817,657],{"emptyLinePlaceholder":20},[220,819,821],{"class":222,"line":820},27,[220,822,823],{"class":651},"  # This tells us the address to a ssh-agent socket (how one can connect to ssh-agent)\n",[220,825,827,829,832,834,837,840,843,846,849,852,855,858,861],{"class":222,"line":826},28,[220,828,758],{"class":757},[220,830,831],{"class":744}," SSH_AUTH_SOCK",[220,833,764],{"class":757},[220,835,836],{"class":230},"`",[220,838,839],{"class":226},"find",[220,841,842],{"class":230}," \u002Ftmp ",[220,844,845],{"class":234},"-type",[220,847,848],{"class":230}," s ",[220,850,851],{"class":234},"-name",[220,853,854],{"class":230}," agent.",[220,856,857],{"class":234},"\\*",[220,859,860],{"class":757}," 2>",[220,862,863],{"class":230},"\u002Fdev\u002Fnull`\n",[220,865,867],{"class":222,"line":866},29,[220,868,869],{"class":744},"  \n",[220,871,873],{"class":222,"line":872},30,[220,874,875],{"class":651},"  # DBUS address is needed to display notify-send messages\n",[220,877,879,882,884,887,890,893],{"class":222,"line":878},31,[220,880,881],{"class":744},"  GNOME_PID",[220,883,764],{"class":757},[220,885,886],{"class":744},"$(",[220,888,889],{"class":226},"pgrep",[220,891,892],{"class":230}," gnome-session",[220,894,895],{"class":744},")\n",[220,897,899,901,904,906,908,911,914,916,919,922,925,928,931,934,937],{"class":222,"line":898},32,[220,900,758],{"class":757},[220,902,903],{"class":744}," DBUS_SESSION_BUS_ADDRESS",[220,905,764],{"class":757},[220,907,886],{"class":744},[220,909,910],{"class":226},"grep",[220,912,913],{"class":234}," -z",[220,915,903],{"class":230},[220,917,918],{"class":230}," \u002Fproc\u002F",[220,920,921],{"class":744},"$GNOME_PID",[220,923,924],{"class":230},"\u002Fenviron",[220,926,927],{"class":757},"|",[220,929,930],{"class":226},"cut",[220,932,933],{"class":234}," -d=",[220,935,936],{"class":234}," -f2-",[220,938,895],{"class":744},[220,940,942],{"class":222,"line":941},33,[220,943,657],{"emptyLinePlaceholder":20},[220,945,947],{"class":222,"line":946},34,[220,948,949],{"class":651},"  # Script execution, in order:\n",[220,951,953],{"class":222,"line":952},35,[220,954,955],{"class":651},"  # \n",[220,957,959],{"class":222,"line":958},36,[220,960,961],{"class":651},"  # - mount the encrypted drive (prompt for password)\n",[220,963,965],{"class":222,"line":964},37,[220,966,967],{"class":651},"  # - close the Nautilus window that pops up for a new mounted device\n",[220,969,971],{"class":222,"line":970},38,[220,972,973],{"class":651},"  # - add the SSH key to ssh-agent (prompt for password)\n",[220,975,977],{"class":222,"line":976},39,[220,978,979],{"class":651},"  # - unmount the encrypted drive\n",[220,981,983],{"class":222,"line":982},40,[220,984,985],{"class":651},"  # - display a notification that the key is loaded\n",[220,987,989],{"class":222,"line":988},41,[220,990,955],{"class":651},[220,992,994],{"class":222,"line":993},42,[220,995,996],{"class":651},"  # if any of the above steps failed, display a failure notification\n",[220,998,1000,1003,1006,1009,1012,1015,1018],{"class":222,"line":999},43,[220,1001,1002],{"class":226},"  veracrypt",[220,1004,1005],{"class":234}," -m",[220,1007,1008],{"class":230}," ro",[220,1010,1011],{"class":744}," $DEVNAME ",[220,1013,1014],{"class":230},"\u002Fmedia\u002Fkeyring",[220,1016,1017],{"class":744}," && ",[220,1019,1020],{"class":234},"\\\n",[220,1022,1024,1027,1030,1032],{"class":222,"line":1023},44,[220,1025,1026],{"class":226},"  killall",[220,1028,1029],{"class":230}," nautilus",[220,1031,1017],{"class":744},[220,1033,1020],{"class":234},[220,1035,1037,1040,1043,1045,1048,1051,1053],{"class":222,"line":1036},45,[220,1038,1039],{"class":226},"  ssh-add",[220,1041,1042],{"class":234}," -c",[220,1044,235],{"class":234},[220,1046,1047],{"class":230}," 8h",[220,1049,1050],{"class":230}," \u002Fmedia\u002Fkeyring\u002Fwork\u002Fid_rsa",[220,1052,1017],{"class":744},[220,1054,1020],{"class":234},[220,1056,1058,1060,1063,1066],{"class":222,"line":1057},46,[220,1059,1002],{"class":226},[220,1061,1062],{"class":234}," -d",[220,1064,1065],{"class":744}," $DEVNAME && ",[220,1067,1020],{"class":234},[220,1069,1071,1074,1077,1080,1083,1086,1089,1092,1095,1097,1100,1103,1105],{"class":222,"line":1070},47,[220,1072,1073],{"class":226},"  sudo",[220,1075,1076],{"class":234}," -u",[220,1078,1079],{"class":744}," $LOGNAME ",[220,1081,1082],{"class":230},"notify-send",[220,1084,1085],{"class":234}," -i",[220,1087,1088],{"class":230}," media-removable",[220,1090,1091],{"class":230}," 'SSH keys loaded'",[220,1093,1094],{"class":230}," \"`",[220,1096,474],{"class":226},[220,1098,1099],{"class":234}," -l",[220,1101,1102],{"class":230},"`\"",[220,1104,1017],{"class":744},[220,1106,1020],{"class":234},[220,1108,1110],{"class":222,"line":1109},48,[220,1111,1112],{"class":234},"  exit\n",[220,1114,1116,1118,1120,1122,1124,1126,1129,1132],{"class":222,"line":1115},49,[220,1117,1073],{"class":226},[220,1119,1076],{"class":234},[220,1121,1079],{"class":744},[220,1123,1082],{"class":230},[220,1125,1085],{"class":234},[220,1127,1128],{"class":230}," emblem-unreadable",[220,1130,1131],{"class":230}," 'Failed to load SSH keys'",[220,1133,1134],{"class":230}," 'Investigate manually'\n",[220,1136,1138],{"class":222,"line":1137},50,[220,1139,1140],{"class":744},"} &\n",[593,1142,1143],{},"html pre.shiki code .sJ8bj, html code.shiki .sJ8bj{--shiki-default:#6A737D;--shiki-dark:#6A737D}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .szBVR, html code.shiki .szBVR{--shiki-default:#D73A49;--shiki-dark:#F97583}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":216,"searchDepth":597,"depth":597,"links":1145},[],"2016-04-13T08:39:08Z",[639,432],{},"anroots","\u002Fgists\u002F25c82171f49aa09390f3a22cf29254db",{"title":632,"description":216},"gists\u002F25c82171f49aa09390f3a22cf29254db","TfLcRokSWUZJAlgF7V44ZIPlFZ70U9RYY6PETnL4EjE",1790228555263]