Public Access
- uname in the console and /uname in IRC: the firmware, its version and the chip - scp: one file between the card and a trusted server, over SSH, with the device's key or a password asked (masked) in the Shell - shared libssh helpers in src/platform/libssh_util - README, user guide, command reference and a how-to updated Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162FokPdvY2KsS4NBfwyWPk
35 lines
1.9 KiB
Markdown
35 lines
1.9 KiB
Markdown
+++
|
|
title = "Log in to a server without a password"
|
|
description = "Make the Cardputer's own SSH key, put its public half on a server, and connect with no password to type."
|
|
weight = 13
|
|
[extra]
|
|
tag = "SSH"
|
|
+++
|
|
|
|
Typing a password on a small keyboard, every time, gets old. With a key, the server recognises the device.
|
|
|
|
1. On the Cardputer, open **SSH → This device's key** and press <kbd>Enter</kbd>. It makes the key and shows its **public half**: one line starting with `ssh-ed25519`.
|
|
2. Get that line to the server. It was also written to the card as **`/ssh/id_ed25519.pub`**, so the easy way is the phone: in **Storage** press <kbd>w</kbd>, open the page ([Move files with your phone](/howto/phone-files/)) and download the file. Or log in to the server with your password, from the Cardputer or anything else, and paste it.
|
|
3. On the server, add the line to the end of **`~/.ssh/authorized_keys`** of the user you log in as:
|
|
|
|
```
|
|
cat id_ed25519.pub >> ~/.ssh/authorized_keys
|
|
chmod 600 ~/.ssh/authorized_keys
|
|
```
|
|
|
|
4. On the Cardputer, connect: **SSH → New connection**, `user@host`. It logs in without asking for anything. The same key is what [`scp`](/howto/scp/) uses.
|
|
|
|
## If it still asks for a password
|
|
|
|
| Check | How |
|
|
|---|---|
|
|
| The line is whole, on one line | `ssh-ed25519`, a long word, then `roro9stack` |
|
|
| The file's permissions | `chmod 700 ~/.ssh` and `chmod 600 ~/.ssh/authorized_keys`: OpenSSH ignores a file others can write |
|
|
| It is the right user's file | the `user` of `user@host` |
|
|
| The server takes keys | `PubkeyAuthentication yes` in its `sshd_config` (the default) |
|
|
| You made a new key since | a new key replaces the old one: put the new line on the server |
|
|
|
|
## Worth knowing
|
|
|
|
The private half never leaves the device and has no passphrase: **whoever holds the Cardputer can log in wherever its key is accepted**. If the device is lost, remove its line from `authorized_keys` on your servers. More in the [SSH](/guide/ssh/) page.
|