ã·ã§ã«ã¹ã¯ãªããã®å¹³æãã¹ã¯ã¼ããã»ãã¥ã¢ã«ããæ¹æ³
追è¨: (2015/8/3) 大éã®ã¯ã¦ããä»ããã®ã§ ç¶ã ãæ¸ãã¾ããã
sshã使ç¨ãã¦ãã人ã¯æååãæ軽ã«æå·åã»å¾©å·åã§ããã¨ãã話ã ãã®ãã¯ããã¯ã使ãã°è²ã ã»ãã¥ã¢ã«ãªãã®ã§ããããã ä»åã¯ã·ã§ã«ã¹ã¯ãªããä¸ã®å¹³æãã¹ã¯ã¼ããã»ãã¥ã¢ã«ä»£æ¿ããã
å¹³æãã¹ã¯ã¼ãã¯ãããã
ã·ã§ã«ã¹ã¯ãªããä¸ã§ãã¹ã¯ã¼ããå¿ è¦ã«ãªã£ãã¨ãã ã¨ããããå¹³æã§æ¸ãã¦ãã¾ããã¡ã
#!/bin/sh PASSWORD="hoge"
ãããã»ãã¥ã¢ã«ãããã é¢åãããã®ã¯å«ãªã®ã§ããªãã¹ãææã¡ã®ãã¼ã«ã§æå·åã復å·åãããã sshç¨ã® rsa ç§å¯éµã¨ãopenssl(大æµã®ç°å¢ã«å ¥ã£ã¦ãã)ã使ã£ã¦æ¹åãããã
ç§å¯éµã®æºå
ãã¹ã¯ã¼ããæå·åããã«ããã£ã¦ãç§å¯éµã使ç¨ããï¼
sshã常ç¨ãã¦ããå ´å㯠~/.ssh/id_rsa
ã¨ããç§å¯éµãåå¨ããã ããã
ããç§å¯éµãç¡ããã° ssh-keygen
ã§ä½æãããã
$ ssh-keygen Generating public/private rsa key pair. Enter file in which to save the key (/home/auewe/.ssh/id_rsa): # ENTER ãæ¼ã Enter passphrase (empty for no passphrase): # ENTER ãæ¼ã Enter same passphrase again: # ENTER ãæ¼ã Your identification has been saved in /home/auewe/.ssh/id_rsa Your public key has been saved in /home/auewe/.ssh/id_rsa.pub The key fingerprint is: 0f:2c:88:3d:40:13:0f:b5:a3:d4:0e:b7:e5:86:28:91 auewe@orenomachine The key's randomart image is: +--[ RSA 2048]----+ | o. | | k = . | | a . a | | o X B . m | |. a B S S | | B o . o | | o | | | | | +-----------------+
ããã§ç§å¯éµ ~/.ssh/id_rsa
ãä½æãããã
openssl ã§æååãæå·åã復å·å
ç§å¯éµ ~/.ssh/id_rsa
ãç¨ãã¦æååããã¡ã¤ã«ãæå·åãã
pass.rsa
ã¨ãããã¡ã¤ã«ã«ä¿åãããã
openssl rsautl -encrypt
ãç¨ããã
- æå·å
# hoge ã¨ããæååãæå·åã㦠pass.rsa ã«æ¸ãè¾¼ãã³ãã³ã $ echo 'hoge' | openssl rsautl -encrypt -inkey ~/.ssh/id_rsa > pass.rsa # plain.txt ã¨ããããã¹ããã¡ã¤ã«ãæå·åã㦠pass.rsa ã«æ¸ãè¾¼ãã³ãã³ã $ openssl rsautl -encrypt -inkey ~/.ssh/id_rsa -in plain.txt > pass.rsa
æå·åå¾ã®ãã¡ã¤ã« pass.rsa
ã復å·åããã«ã¯
openssl rsautl -decrypt
ãç¨ããã
- 復å·å
# æå·åããã pass.rsa ã復å·åãã¦æ¨æºåºåã«è¡¨ç¤ºããã³ãã³ã $ openssl rsautl -decrypt -inkey ~/.ssh/id_rsa -in pass.rsa
å¾ã£ã¦ãåé ã®ã¤ã³ã»ãã¥ã¢ãªã·ã§ã«ã¹ã¯ãªããã¯æ¬¡ã®ããã«æ¸ãæãããã
#!/bin/sh # æå·åããããã¹ã¯ã¼ããã¡ã¤ã« pass.rsa ã¯ããããããç¨æãã¦ãã PASSWORD=$(openssl rsautl -decrypt -inkey ~/.ssh/id_rsa -in pass.rsa)
è£è¶³
æå·åã復å·åãç§å¯éµã使ç¨ãããã
æå·åã«é¢ãã¦è¨ãã¨ãåççã«ã¯å
¬ééµ ~/.ssh/id_rsa.pub
ãç¨ããã°
pass.rsa ãå¾ãããã¯ãã ã
ä»åã¯ç§å¯éµãã¡ã¤ã«ä¸ã«å«ã¾ããå
¬ééµã®æ
å ±ãç¨ãã¦æå·åãã¦ããã