Computer Stuff

Jun 20, 2014

Disable password authentication in ssh server

As part of my internship at Savoir-faire Linux I had to configure an ssh server for Kerberos authentication, and to make sure I would log in with my Kerberos password and not my server’s local account, I wanted to disable password authentication altogether.

The first option that comes to mind is PasswordAuthentication defined in rfc 4252 section 8. PasswordAuthentication allows an authentication method in which the client will prompt the user for his password and will then send it to the server. This is what the sshd_config file comments as ‘tunneled clear text password’. If you connect to the server with the -v flag, this is the “password” method.

However if you disable this option you might find that password authentication still works. And this is where the option ChallengeResponseAuthentication as defined in rfc 4256(yes I looked for the rfc , the manuals wasn’t clear about these options) comes in action. ChallengeResponseAuthentication allows an authentication method in which the server sends a challenge to the client, with its associated instructions and prompts, to which the user must often keyboard-interactively answer to. ChallengeResponseAuthentication won’t work if sshd has no challenge to propose to the client. The challenges aren’t defined in sshd. The challenges come from PAM modules or other authentication schemes that might be enabled. This is the “keyboard-interactive” method.

On most distros, the default for PAM is to ask the password against the local database.

So to disable password authentication, you should set PasswordAuthentication to no AND ChallengeResponseAuthentication or UsePAM to no. Otherwise you could also change defaults PAM settings, but it is trickier/dangerous if you don’t already know PAM.

Jun 19, 2014

How to use tabs in vim

My friend depier.re convinced me to use tabs in vim. It might indeed improve my productivity as I have the habit of opening several vim instances for different files of the same project.

To open several files in tabs, you can issue this command:

vim -p file1 file2

Or you can also open a new tab with:

:tabedit <filename>

Then you can use the following commands to switch between next, and previous tabs:

:tabn
:tabp

Hopefully we can map those commands to more convenient keys. You can write the following in your .vimrc file:

unmap <C-j>
unmap <C-k>
iunmap <C-k>

nmap <C-k> :tabp<CR>
vmap <C-k> :tabp<CR>
imap <C-k> <Esc>:tabp<CR>
nmap <C-j> :tabn<CR>
vmap <C-j> :tabn<CR>
imap <C-j> <Esc>:tabn<CR>

This way you’ll be able to switch tabs using <C-j> or <C-k> in normal, viusal or even insert mode.

Another nice trick he showed me is to bind ;t to tabnew:

cnoreabbrev t tabnew
nnoremap ; :
vnoremap ; :

Finally i remaped split keys to easier combinations:

nnoremap <C-h> <C-w><C-h>
nnoremap <C-l> <C-w><C-l>
← Previous Page 2 of 2