karaf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Guillaume Nodet (Commented) (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (KARAF-32) Support ssh public key authentication and agent forwarding
Date Tue, 31 Jan 2012 11:56:10 GMT

    [ https://issues.apache.org/jira/browse/KARAF-32?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13196853#comment-13196853
] 

Guillaume Nodet commented on KARAF-32:
--------------------------------------

Why not checking the last modified date of the file and reload if needed when the authentication
is performed.  I'd go even further and reload each time as done with the JAAS realm.  I don't
really think it's a problem given karat is not really meant to receive thousands of ssh connections.
                
> Support ssh public key authentication and agent forwarding
> ----------------------------------------------------------
>
>                 Key: KARAF-32
>                 URL: https://issues.apache.org/jira/browse/KARAF-32
>             Project: Karaf
>          Issue Type: New Feature
>            Reporter: Guillaume Nodet
>            Assignee: Jean-Baptiste Onofré
>         Attachments: org.apache.karaf.shell.ssh-2.2.5-pubkey-userauthfactories.patch,
org.apache.karaf.shell.ssh-2.2.5-pubkey-userauthfactories.patch
>
>
> The karaf agent needs to be enhanced to be able to set up an ssh agent and use a public/private
key.
> The ssh server need to be configured with a public key authentication that could delegate
to the KeystoreInstance using certificates.
> The goal would be support the following use cases:
>   * once a user is logged into a given karaf instance, he can connect to any other instance
(provided that the public key is supported)
>   * the stop script could use the ssh agent so that you don't need to launch it with
a password on the command line
> A set of commands to administer the keystores might be interesting (maybe a console plugin
too, but we need to check with what Geronimo provides in this area). 
> Btw,  I wonder if Apache Shiro would help in any way for all the security stuff.
>   

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

       

Mime
View raw message