A2 - Stop Typing Your Password
Week 4 · 20 points · pass/fail · one paper worksheet per group, turned in before you leave
Why you are doing this
Last week you typed your Onyx password a dozen times. Today you type it twice more and then never again. Along the way you learn what SSH is actually doing when it logs you in, why the second login is faster than the first, and how to teach the shell a new word that is still there tomorrow.
Two of those words matter for the rest of the course. ssh onyx is how you will reach the box for every project from here on. probe is a quick connection test you can reach for whenever something will not connect; you do not need to understand what is inside it yet, you just need it to exist.
This one is instructor led. I do each step on the projector, you do it on your laptop, and we do not move on until the room has caught up. Nobody is racing anybody.
WARNING
One paper worksheet per group, turned in before you leave. It is short: a row per person, two timings, and three questions. Graded pass/fail; a serious attempt at every step is a pass.
Before you start
- Sit with your group from A1, so the person next to you can help when your laptop does something mine did not.
- You need the SSH client you used in A1. On Windows, use Git Bash today. Two commands differ there: if
ssh-copy-idis missing, use the by-hand steps in step 2, and useping -n 3instead ofping -c 3in step 4. - The editor today is
vi. It is on Onyx, on every Linux box you will ever ssh into, and in Git Bash. You need six things, and they are on the board:ito start typing,Escto stop,:wqto save and quit,:q!to bail out without saving,Gto jump to the end of the file, andoto open a new line below the cursor.
Step 0 - Prove you can get there at all
Before we change anything, every member confirms that plain password login works. On your laptop:
ssh <username>@onyx.boisestate.eduThree things can happen, and only the first two are good:
- It asks
Are you sure you want to continue connecting (yes/no)?the first time. Typeyes. That is your laptop remembering Onyx's fingerprint. - It asks for your password, you type it, and you get a prompt on Onyx. Run
exitto come back. Write "yes" in the step 0 column on the worksheet. - Anything else. Stop here and fix it, because nothing after this step will work until this does.
Hands up when everyone in your group has a prompt on Onyx and has typed exit.
If it did not work
The message ssh printed tells you where it stopped. Find yours:
| What you saw | What it means | What to do |
|---|---|---|
ssh: command not found or 'ssh' is not recognized | Your laptop has no SSH client on its path | Windows: open Git Bash instead of PowerShell or cmd. |
Could not resolve hostname | Your laptop could not turn the name into an address | Check the spelling: onyx.boisestate.edu. Then check you have a network at all: curl -I https://www.boisestate.edu/. If that fails too, it is the Wi-Fi, not SSH. |
Hangs, then Connection timed out | Packets left your laptop and nothing came back | Try a different network (a phone hotspot is the quickest test). If it works there, something on the first network is blocking port 22. |
Connection refused | You reached a machine and it is not running SSH | Almost always the hostname is wrong and you reached something else. Check it character by character. |
Permission denied (publickey,password) after typing a password | You reached Onyx and it rejected the login | The username is your Boise State username, not your email address. Retype the password slowly; nothing is echoed. Three failures in a row and you may not have an Onyx account yet, which is fixed outside this room: tell me. |
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! | Your laptop has an old fingerprint for Onyx | ssh-keygen -R onyx.boisestate.edu, then try again and answer yes. |
When the table does not cover it, ask ssh to narrate what it is doing:
ssh -v <username>@onyx.boisestate.eduRead the last few lines before it stopped. Connecting to ... with nothing after it is the network. Authentications that can continue followed by a failure is the account. Show the person next to you; two people reading -v output solve it faster than one.
Step 1 - Make a key
On your laptop:
ssh-keygen -t ed25519 -C "you@boisestate.edu"Press Enter to accept the default file, and Enter twice more for no passphrase. That makes two files in ~/.ssh: id_ed25519, which is private and never leaves this laptop, and id_ed25519.pub, which is public and is the half you hand out.
ls -l ~/.ssh
cat ~/.ssh/id_ed25519.pubHands up when you can see one line starting with ssh-ed25519 on your screen.
Step 2 - Put the public half on Onyx
Still on your laptop:
ssh-copy-id <username>@onyx.boisestate.eduThat is the second of today's two password prompts, and the last one. It appends your public key to ~/.ssh/authorized_keys on Onyx.
If ssh-copy-id is missing, do it by hand. Copy the ssh-ed25519 line from step 1, log into Onyx, and:
mkdir -p ~/.ssh
echo 'ssh-ed25519 AAAA... you@boisestate.edu' >> ~/.ssh/authorized_keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keysThe two chmod lines matter. SSH silently ignores the file if anybody else on the machine could write to it (or to ~/.ssh), and "silently" is the important word.
Now the test, from your laptop:
ssh <username>@onyx.boisestate.edu uname -nNo password prompt, and it prints onyx. That is the first line on the worksheet.
Hands up when that works with no password. If it asks for one anyway, the permissions are almost always why; say so and we fix it together. Write "yes" in the step 2 column on the worksheet.
Step 3 - Make it one word
Create ~/.ssh/config on your laptop with vi ~/.ssh/config. Press i, type this in, press Esc, then :wq:
Host onyx
HostName onyx.boisestate.edu
User <username>
IdentityFile ~/.ssh/id_ed25519
ServerAliveInterval 60
ControlMaster auto
ControlPath ~/.ssh/cm-%r@%h:%p
ControlPersist 10mThen:
chmod 600 ~/.ssh/config
ssh onyx uname -nFrom now on, ssh onyx is all you type. The first four lines are the shortcut. ServerAliveInterval keeps an idle session from being dropped. The last three are the next step.
Hands up when ssh onyx uname -n prints onyx.
Step 4 - Measure what the second login saves
Those last three lines turn on connection multiplexing: the first connection stays open for ten minutes after you log out, and later ones reuse it instead of paying for a new TCP handshake and a new key exchange.
Measure it. On your laptop:
ssh -O exit onyx 2>/dev/null # tear down any existing master
time ssh onyx true # cold: full setup
time ssh onyx true # warm: reuses the open connectionPut both numbers in your row on the worksheet, and get one more number:
ping -c 3 onyx.boisestate.eduThat is the round trip time between your laptop and Onyx. Then answer, as a group: the cold login cost some number of round trips. Roughly how many, and what was it doing in them? You saw the TCP handshake in the reading; SSH adds a version exchange, a key exchange, and authentication on top.
Step 5 - Where bash reads its configuration
Now on Onyx. When you log in, bash reads a file before it gives you a prompt, and anything you put in that file is there every time. On Red Hat, a login shell reads ~/.bash_profile, and the default one sources ~/.bashrc. Look:
cat ~/.bash_profile
head -20 ~/.bashrcLook near the top of ~/.bashrc for a line like [ -z "$PS1" ] && return. On Onyx there is no such line. On many other systems there is, and it makes the file give up immediately for any shell that is not interactive. Write down whether yours has one; step 7 depends on it.
Step 6 - Teach the shell a new word
On Onyx, open ~/.bashrc with vi ~/.bashrc. Press G to jump to the last line, o to open a new line below it, and type this in. Then Esc and :wq.
# CS425: probe a host and port, report how long each phase took
probe() {
curl -sS -o /dev/null -m 8 \
-w 'connect=%{time_connect} total=%{time_total} code=%{http_code}\n' \
"http://$1:$2/"
}Save and exit. The curl line makes one HTTP request and throws the page away (-o /dev/null), gives up after 8 seconds (-m 8), and prints how long the TCP connection took to open, how long the whole request took, and the HTTP status code (-w). The rest of the flags are in man curl. What matters today is the shape: probe is a function, $1 is the first thing you type after it and $2 is the second.
Load it into the shell you are sitting in, then check it took:
source ~/.bashrc
type probe # should say "probe is a function"
probe example.com 80Write what probe example.com 80 printed on the worksheet.
Hands up when type probe says it is a function. If it says not found, the edit did not save; open the file again and look at the bottom.
Step 7 - Prove it is permanent
This is the actual point. A function typed at the prompt dies with the terminal. One in ~/.bashrc does not. Prove it two ways:
Log out of Onyx completely (
exit). Log back in withssh onyx. Runprobe example.com 80again without sourcing anything.From your laptop, run:
bashssh onyx probe example.com 80That is a non-interactive shell: no prompt, no terminal, just one command. It still works, because bash reads
~/.bashrcwhen a remote shell daemon starts it, and Onyx has no guard line stopping it.
On the worksheet, in one sentence: why would the second one fail on a machine whose ~/.bashrc began with [ -z "$PS1" ] && return?
Step 8 - Why a function and not an alias
Try it the other way. On Onyx, at the prompt:
alias probe2='curl -sS -o /dev/null -m 8 -w "code=%{http_code}\n"'
probe2 http://example.com/That works, because the thing you type lands at the end, where a URL happens to go. Now try to make probe2 example.com 80 build http://example.com:80/ out of two separate words. You cannot: an alias is text pasted in front of what you typed, and there is no way to say "put the second word here". A function has $1 and $2. That is the entire reason probe is a function.
Answer the last question on the worksheet.
Step 9 - Same function, your laptop
Onyx tests a connection from campus. To test one from the network you are actually on, put probe on your laptop too. Open ~/.bashrc on your laptop (on Windows, from Git Bash, and on a Mac, whose shell is zsh, open ~/.zshrc instead), paste the same function at the bottom, open a new terminal window, and run probe example.com 80. If it prints a code=200 line, you are done.
Checkpoint
Every member logs into Onyx with no password using ssh onyx, the group has cold and warm timings for everyone, and probe survives a logout on Onyx and works on at least one laptop.
Worksheet
Download: a2-worksheet.pdf
The printed worksheet is one page: a row per member (laptop OS, password login works, key login works, cold and warm timings), the round trip estimate, whether your ~/.bashrc has a guard line, what probe printed, and the two written questions.