Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 381813 - Add new SSH key for leio
Summary: Add new SSH key for leio
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Gentoo Overlays (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Overlays Project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-09-04 18:44 UTC by Mart Raudsepp
Modified: 2014-10-20 08:44 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mart Raudsepp gentoo-dev 2011-09-04 18:44:23 UTC
As a standard security practice, I maintain unique SSH private keys per machine. I have added the new work laptop SSH key to LDAP, but overlay doesn't seem to consult with it.

Please add overlay access to the leio@daedalus key in LDAP to all overlays I have relevant access to. This can be retrieved from perl_ldap -s leio on woodpecked of course.
Access to the leio@martr-gentoo SSH key can be removed now as well, while at it - that key is out of my control now from my previous job work machine.
Comment 1 Christian Ruppert (idl0r) gentoo-dev 2011-09-04 19:00:40 UTC
leio@martr-gentoo removed, leio@yeeloong and leio@daedalus added.
Comment 2 Mart Raudsepp gentoo-dev 2013-04-12 20:08:44 UTC
As automatic sync with LDAP still doesn't seem to be implemented, I now have the following updates:

leio@daedalus can be removed - don't have that machine anymore and I shredded my content after partial backup to phoenix, but more secure to remove pubkey regardless.

leio@asustmp needs to be added - this is now my current (possibly temporary, but private key would get shredded once in my hands anymore) work laptop with mostly up to date gentoo, on which I'd like to do some gnome and x11 overlays work, maybe more out of the overlays I have access to.

leio@odyssey is a desktop machine that currently has broken graphics card, so out of commission - but privkey is safe in the powered off machine in the corner. Unsure if and when it gets revived; so no need to add this key immediately, but can be for the sake of synced with LDAP.

stable@phoenix is a key in a chroot; no matter with that, I can also access overlays outside the chroot if needed.
Comment 3 Thomas Sachau gentoo-dev 2013-04-20 09:05:55 UTC
(In reply to comment #2)
> As automatic sync with LDAP still doesn't seem to be implemented, I now have
> the following updates:
> 
> leio@daedalus can be removed - don't have that machine anymore and I
> shredded my content after partial backup to phoenix, but more secure to
> remove pubkey regardless.
> 
> leio@asustmp needs to be added - this is now my current (possibly temporary,
> but private key would get shredded once in my hands anymore) work laptop
> with mostly up to date gentoo, on which I'd like to do some gnome and x11
> overlays work, maybe more out of the overlays I have access to.
> 
> leio@odyssey is a desktop machine that currently has broken graphics card,
> so out of commission - but privkey is safe in the powered off machine in the
> corner. Unsure if and when it gets revived; so no need to add this key
> immediately, but can be for the sake of synced with LDAP.
> 
> stable@phoenix is a key in a chroot; no matter with that, I can also access
> overlays outside the chroot if needed.

leio@daedalus removed
leio@asustmp added
stable@phoenix added
Comment 4 Mart Raudsepp gentoo-dev 2014-10-15 13:15:22 UTC
Please add leio@localhost key from LDAP (and implement LDAP sync :D). Can be named leio@orion if you don't like localhost as it was generated before hostname setting. It is my main work and gentoo development machine right now.

In lack of LDAP sync I partly gave up on separate SSH keys and am reusing one of the existing ones on my ARM setups that use overlays... which is sad, but reopening this bug for each of those would get bothersome really fast.
Comment 5 Pavlos Ratis (RETIRED) Gentoo Infrastructure gentoo-dev 2014-10-20 08:44:43 UTC
(In reply to Mart Raudsepp from comment #4)
> Please add leio@localhost key from LDAP (and implement LDAP sync :D). Can be
> named leio@orion if you don't like localhost as it was generated before
> hostname setting. It is my main work and gentoo development machine right
> now.
> 
> In lack of LDAP sync I partly gave up on separate SSH keys and am reusing
> one of the existing ones on my ARM setups that use overlays... which is sad,
> but reopening this bug for each of those would get bothersome really fast.

New key added.