Files
twislaandClaude Opus 5.5 6b71aace4f
CI / build (pull_request) Successful in 2m22s
Site / build (pull_request) Successful in 10s
SSH client: a terminal on another machine (#2)
The SSH App opens one session to a shell, over libssh (LibSSH-ESP32 5.10.0)
on mbedTLS. A server is trusted the first time on its fingerprint, and a
changed key is a warning with Cancel selected. The password is typed each
time and kept nowhere; or the device makes itself an Ed25519 key, whose
public half is shown, written to /ssh/id_ed25519.pub and printed by
`ssh status`.

lib/term is the terminal: what a shell, less, top, nano and vim send, with
sixteen colours, scroll regions, the alternate screen and 100 lines of
scrollback. Five text sizes with Ctrl and + or -, from 60x20 to 26x8, told
to the far end. The session goes on when the App is left; SSH shows in the
Status Bar. `ssh user@host` in the Shell opens the App.

Also:
- Keys that aren't characters carry Shift, Ctrl and Alt. The terminal needs
  it, and it makes Ctrl+Fn+up/down in a note and Shift+Tab in Gemini work
  from the real keyboard.
- IRC doesn't try to connect under 60 KB free: started with a session open,
  its TLS handshake took the heap down to 236 bytes.
- libssh's own curve25519 is left out of the build (scripts/libssh_filter.py):
  libsodium's has the same names.

Costs 292 KB of flash and about 50 KB of heap while a session is open; not
started under 75 KB free.

Docs: guide page, how-to, FAQ, home page, Status Bar, SD card folders, the
memory how-to, README, glossary, N1 notes with Q254 to Q266 and the checks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
2026-10-08 04:38:36 +02:00

35 lines
1.9 KiB
Markdown

+++
title = "Log in to a server without a password"
description = "Make the Cardputer's own SSH key, put its public half on a server, and connect with no password to type."
weight = 13
[extra]
tag = "SSH"
+++
Typing a password on a small keyboard, every time, gets old. With a key, the server recognises the device.
1. On the Cardputer, open **SSH → This device's key** and press <kbd>Enter</kbd>. It makes the key and shows its **public half**: one line starting with `ssh-ed25519`.
2. Get that line to the server. It was also written to the card as **`/ssh/id_ed25519.pub`**, so the easy way is the phone: in **Storage** press <kbd>w</kbd>, open the page ([Move files with your phone](/howto/phone-files/)) and download the file. Or log in to the server with your password, from the Cardputer or anything else, and paste it.
3. On the server, add the line to the end of **`~/.ssh/authorized_keys`** of the user you log in as:
```
cat id_ed25519.pub >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
```
4. On the Cardputer, connect: **SSH → New connection**, `user@host`. It logs in without asking for anything.
## If it still asks for a password
| Check | How |
|---|---|
| The line is whole, on one line | `ssh-ed25519`, a long word, then `roro9stack` |
| The file's permissions | `chmod 700 ~/.ssh` and `chmod 600 ~/.ssh/authorized_keys`: OpenSSH ignores a file others can write |
| It is the right user's file | the `user` of `user@host` |
| The server takes keys | `PubkeyAuthentication yes` in its `sshd_config` (the default) |
| You made a new key since | a new key replaces the old one: put the new line on the server |
## Worth knowing
The private half never leaves the device and has no passphrase: **whoever holds the Cardputer can log in wherever its key is accepted**. If the device is lost, remove its line from `authorized_keys` on your servers. More in the [SSH](/guide/ssh/) page.