From owner-freebsd-questions@FreeBSD.ORG Tue Oct 21 18:35:15 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E1D2F10656A1 for ; Tue, 21 Oct 2008 18:35:15 +0000 (UTC) (envelope-from jalmberg@identry.com) Received: from mx1.identry.com (on.identry.com [66.111.0.194]) by mx1.freebsd.org (Postfix) with ESMTP id 7AD298FC1A for ; Tue, 21 Oct 2008 18:35:15 +0000 (UTC) (envelope-from jalmberg@identry.com) Received: (qmail 54580 invoked by uid 89); 21 Oct 2008 18:35:14 -0000 Received: from unknown (HELO ?192.168.1.110?) (jalmberg@75.127.142.66) by mx1.identry.com with ESMTPA; 21 Oct 2008 18:35:14 -0000 Mime-Version: 1.0 (Apple Message framework v753.1) In-Reply-To: <48FD47E6.8040201@boosten.org> References: <1479DAD4-A72B-415E-B8B0-FDEA810161ED@identry.com> <6E564226-98BE-4464-BA6C-A95848F02ABC@identry.com> <48FD47E6.8040201@boosten.org> Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <1D3A7106-EEEB-4D89-99A6-7B4E3F9B17DD@identry.com> Content-Transfer-Encoding: 7bit From: John Almberg Date: Tue, 21 Oct 2008 14:35:13 -0400 To: freebsd-questions@freebsd.org X-Mailer: Apple Mail (2.753.1) Subject: Re: mysql connection through ssl tunnel X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 21 Oct 2008 18:35:16 -0000 On Oct 20, 2008, at 11:09 PM, Peter Boosten wrote: > John Almberg wrote: >> >> I tried this, and not surprisingly, it didn't work. Now I'm trying to >> debug it... >> > > Maybe some mixup in the keys? In my example ssh tries to read the > private key of root on the connecting server, so the server where the > database is located, because init is run as root. If you need another > key, then you need to specify this with the -i parameter. > Ah... that makes sense. I had set up the keys for 'admin', but of course init is run by root. Duh. That raises another issue... I don't allow root logins on either server, for security reasons... Peter, I appreciate your ideas and help, but I think I will stick with autossh, probably by finally learning how to create an rc.d script (not sure the actual name for these, but you know what I mean.) I've actually got autossh working, and think it's a simpler solution for me. Thanks. Brgds: John