From owner-freebsd-doc@FreeBSD.ORG Wed Oct 3 19:50:02 2007 Return-Path: Delivered-To: freebsd-doc@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 339F216A41B for ; Wed, 3 Oct 2007 19:50:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 0320B13C448 for ; Wed, 3 Oct 2007 19:50:02 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.1/8.14.1) with ESMTP id l93Jo1EY079176 for ; Wed, 3 Oct 2007 19:50:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.1/8.14.1/Submit) id l93Jo1MI079175; Wed, 3 Oct 2007 19:50:01 GMT (envelope-from gnats) Resent-Date: Wed, 3 Oct 2007 19:50:01 GMT Resent-Message-Id: <200710031950.l93Jo1MI079175@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-doc@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Warren Block Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AFD6E16A419 for ; Wed, 3 Oct 2007 19:41:33 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [IPv6:2001:4f8:fff6::21]) by mx1.freebsd.org (Postfix) with ESMTP id 9117313C447 for ; Wed, 3 Oct 2007 19:41:33 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.14.1/8.14.1) with ESMTP id l93JfXca047752 for ; Wed, 3 Oct 2007 19:41:33 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.14.1/8.14.1/Submit) id l93JfXdN047751; Wed, 3 Oct 2007 19:41:33 GMT (envelope-from nobody) Message-Id: <200710031941.l93JfXdN047751@www.freebsd.org> Date: Wed, 3 Oct 2007 19:41:33 GMT From: Warren Block To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.1 Cc: Subject: docs/116879: [patch] ssh-keygen not clear whether authorized_keys is file or dir X-BeenThere: freebsd-doc@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Documentation project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Oct 2007 19:50:02 -0000 >Number: 116879 >Category: docs >Synopsis: [patch] ssh-keygen not clear whether authorized_keys is file or dir >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-doc >State: open >Quarter: >Keywords: >Date-Required: >Class: doc-bug >Submitter-Id: current-users >Arrival-Date: Wed Oct 03 19:50:01 GMT 2007 >Closed-Date: >Last-Modified: >Originator: Warren Block >Release: 6.2-STABLE >Organization: >Environment: FreeBSD speedy.wonkity.com 6.2-STABLE FreeBSD 6.2-STABLE #0: Fri Sep 28 13:51:02 MDT 2007 root@speedy.wonkity.com:/usr/obj/usr/src/sys/SPEEDY i386 >Description: The Handbook OpenSSH/ssh-keygen section says "The public key must be placed in ~/.ssh/authorized_keys of the remote machine in order for the setup to work. Similarly, RSA version 1 public keys should be placed in ~/.ssh/authorized_keys." The usage of "in" is ambiguous, and can be read as "place the key file in a directory called authorized_keys". >How-To-Repeat: Read the OpenSSH/ssh-keygen section of the Handbook. >Fix: Apply the attached patch. Patch attached with submission follows: --- chapter.sgml.orig 2007-10-03 12:38:49.000000000 -0600 +++ chapter.sgml 2007-10-03 13:36:46.000000000 -0600 @@ -4221,11 +4221,11 @@ ~/.ssh/id_rsa, whereas the public key is stored in ~/.ssh/id_dsa.pub or ~/.ssh/id_rsa.pub, respectively for DSA and - RSA key types. The public key must be placed in - ~/.ssh/authorized_keys of the remote - machine in order for the setup to work. Similarly, RSA version - 1 public keys should be placed in - ~/.ssh/authorized_keys. + RSA key types. The public key must be placed in the + ~/.ssh/authorized_keys file of the remote + machine in order for the setup to work. Both DSA and RSA version + 1 public keys may be placed in the + ~/.ssh/authorized_keys file. This will allow connection to the remote machine based upon SSH keys instead of passwords. >Release-Note: >Audit-Trail: >Unformatted: