Managing public SSH keys for ksadmin
The ksadmin user, is a specialized operating system administrator that can access the CipherTrust Manager via SSH or via password authentication on a physical server console port. Additionally, you can also enhance the access by adding more public SSH keys for the ksadmin user to connect securely to the CipherTrust Manager.
To add additional public SSH keys:
From ksadmin home, list the directories using
-aoption. Since the.sshfolder is hidden.Alternatively, use WinSCP. Go to Options > Preferences > Panels and select Show Hidden Files.
Modify the
authorized_keysfile directly in Windows to add the new SSH public key. Or, use WinSCP.Reboot the system.
Example
Below is an example of file modification.
Original file
Command:
ksadmin@keysecure:~/.ssh$ cat authorized_keys.original
Output:
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCWOup8bpe+f3fB7R8/JbpnMASDcF+UiNdUDAMYAtiiE2DXPW2ZKqyggOo1pYc4FR6aovoqyWo2q+MhXk+UUdBa3RrdOprRUedP0ZcoHnKyvimGscUUSzFRQPi7TlPVl60zfSoxAZQCa2YH1R4JCUv0hzmL3XAY9JoLnPwML+eq6uLUzYXvaoVqVNNZd0X5zX4O/YdbaDvmIO4IBc6f2Er+Rzp07mMN61Y6XOA2G4ULLUV1APnVwmAoFELnBxjyFYT7liP/uizI6dxviU4SDXyBWXvL54kw5+1IHjGztXdddeqB2hv7ZvvEl7XdNanVUYefTJ019j82TDz+7i/p9Nel PV-Linux-keypair_PUBLIC
Modified file
Command:
ksadmin@keysecure:~/.ssh$ cat authorized_keys
Output:
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCWOup8bpe+f3fB7R8/JbpnMASDcF+UiNdUDAMYAtiiE2DXPW2ZKqyggOo1pYc4FR6aovoqyWo2q+MhXk+UUdBa3RrdOprRUedP0ZcoHnKyvimGscUUSzFRQPi7TlPVl60zfSoxAZQCa2YH1R4JCUv0hzmL3XAY9JoLnPwML+eq6uLUzYXvaoVqVNNZd0X5zX4O/YdbaDvmIO4IBc6f2Er+Rzp07mMN61Y6XOA2G4ULLUV1APnVwmAoFELnBxjyFYT7liP/uizI6dxviU4SDXyBWXvL54kw5+1IHjGztXdddeqB2hv7ZvvEl7XdNanVUYefTJ019j82TDz+7i/p9Nel PV-Linux-keypair_PUBLIC
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC9o5irVdzR1GNQwt+oQP/5t9IzsdwTROw3Q2qBG+OSkbExAdSRnNydAGmsJ6H5kAaKUYMnOYX7xPphgGYLmocZ/eba7fAqFfnAlYYWL91bQ61PDTnV1S/HJ0tLynRWHUROvGZInzMfCrRuHqqNMpuhQ7OopisY4wwQ57XtUi8sRrLNjEYiQRL7oJc5EajFe5Mgr47KGCs2o1EX2VgxLdmphu4XVWrA/9YbqMjE+HMXrP1MURofluompiT/GKjMZpbHUMQfHlHK9b7YYTtUGixhDVI46pFm3YQ50ETO5HZAwwep7ySqNFJ4tbBT86kpexG+8ktHw5PYaFsh1gk4nlY5 SEG-kylo_public