Hardening your Pinebook Pro
#13
One other thing that probably should be done, is re-create the host SSH keys. SSH host keys should be unique per host. From what I can tell, the default Debian comes with host SSH keys already created from July 11, 2019;
Code:
# ls -l ssh_host_*
-rw------- 1 root root  668 Jul 11 16:55 ssh_host_dsa_key
-rw-r--r-- 1 root root  609 Jul 11 16:55 ssh_host_dsa_key.pub
-rw------- 1 root root  227 Jul 11 16:55 ssh_host_ecdsa_key
-rw-r--r-- 1 root root  181 Jul 11 16:55 ssh_host_ecdsa_key.pub
-rw------- 1 root root  411 Jul 11 16:55 ssh_host_ed25519_key
-rw-r--r-- 1 root root  101 Jul 11 16:55 ssh_host_ed25519_key.pub
-rw------- 1 root root 1675 Jul 11 16:55 ssh_host_rsa_key
-rw-r--r-- 1 root root  401 Jul 11 16:55 ssh_host_rsa_key.pub
Plus, remove the in-secure DSA host key.


Here is how to do it.
As user "root", simply run the following commands. If you like, you can put the hostname in the comment, like "MyHost rsa hostkey".
Code:
cd /etc/ssh
rm ssh_host_*
ssh-keygen -t 4096 -t rsa -C "rsa hostkey" -f ./ssh_host_rsa_key
ssh-keygen -t 521 -t ecdsa -C "ecdsa hostkey" -f ./ssh_host_ecdsa_key
ssh-keygen -t ed25519 -C "ed25519 hostkey" -f ./ssh_host_ed25519_key
Note that you will be asked for a passphrase. Per SSH manual page, host keys must have an empty passphrase. Simply hit return when prompted, (twice per key).
--
Arwen Evenstar
Princess of Rivendale


Messages In This Thread
Hardening your Pinebook Pro - by Arwen - 11-12-2019, 08:34 PM
RE: Hardening your Pinebook Pro - by PineFan - 11-12-2019, 11:07 PM
RE: Hardening your Pinebook Pro - by DrYak - 11-13-2019, 10:15 AM
RE: Hardening your Pinebook Pro - by hdk - 11-13-2019, 12:44 AM
RE: Hardening your Pinebook Pro - by xalius - 11-13-2019, 03:59 AM
RE: Hardening your Pinebook Pro - by Arwen - 11-13-2019, 05:29 AM
RE: Hardening your Pinebook Pro - by Arwen - 11-23-2019, 05:51 PM
RE: Hardening your Pinebook Pro - by hdk - 11-24-2019, 01:17 AM
RE: Hardening your Pinebook Pro - by Arwen - 11-24-2019, 11:36 AM
RE: Hardening your Pinebook Pro - by hdk - 11-25-2019, 12:16 AM
RE: Hardening your Pinebook Pro - by e-minguez - 11-25-2019, 03:27 AM
RE: Hardening your Pinebook Pro - by Arwen - 11-25-2019, 06:11 AM
RE: Hardening your Pinebook Pro - by Arwen - 12-07-2019, 02:56 PM
RE: Hardening your Pinebook Pro - by ElektromAn - 12-09-2019, 11:07 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Boot Order in Pinebook Pro food 11 5,662 03-28-2025, 10:08 AM
Last Post: DrYak
  Upgrading Armbian from v24.2.1 gnome, breaks pinebook pro Sb2024 0 621 11-10-2024, 02:50 PM
Last Post: Sb2024
  Pinebook pro won't boot after bootloader installation jwensouls 4 2,424 08-21-2024, 04:17 AM
Last Post: KC9UDX
  [Pinebook Pro/Mobian/XFCE4] can fix touch or screen in greeter not both SynthGal 0 893 05-31-2024, 09:42 AM
Last Post: SynthGal
  Debian on Pinebook Pro u974615 7 4,837 03-31-2024, 10:11 AM
Last Post: u974615
  Pinebook Pro upgrading from the factory image yamsoup 12 7,397 02-22-2024, 04:02 PM
Last Post: tllim
  Help installing Manjaro on eMMC of Pinebook Pro pine4546464 4 4,495 12-13-2023, 07:22 PM
Last Post: trillobite
  Need Help Recovering Manjaro /boot Contents on Pinebook Pro calinb 6 5,162 12-11-2023, 03:47 AM
Last Post: calinb
  Gentoo on Pinebook Pro RELEASE jannik2099 54 121,664 12-08-2023, 11:25 PM
Last Post: tllim
  PineBook Pro seems to go to deep sleep, but doesn't wake up pogo 11 10,150 08-31-2023, 04:20 PM
Last Post: TRS-80

Forum Jump:


Users browsing this thread: 1 Guest(s)