Some typo fixes
This commit is contained in:
parent
fea7fe3ef3
commit
140625035a
1 changed files with 4 additions and 4 deletions
|
|
@ -648,7 +648,7 @@ Where `ssh-rsa _AAAAB5Wm._pass:attributes[{blank}]` is the contents of `ca_host_
|
|||
[[sec-Signing_SSH_Certificates]]
|
||||
=== Creating SSH Certificates
|
||||
|
||||
A certifcate is a signed public key. The user's and host's public keys must be copied to the CA server for signing by the CA server's private key.
|
||||
A certificate is a signed public key. The user's and host's public keys must be copied to the CA server for signing by the CA server's private key.
|
||||
|
||||
[IMPORTANT]
|
||||
====
|
||||
|
|
@ -750,7 +750,7 @@ HostCertificate /etc/ssh/ssh_host_rsa_key-cert.pub
|
|||
~]#{nbsp}systemctl restart sshd.service
|
||||
----
|
||||
|
||||
. On user's systems. remove keys belonging to hosts from the `~/.ssh/known_hosts` file if the user has previously logged into the host configured above. When a user logs into the host they should no longer be presented with the warning about the hosts authenticity.
|
||||
. On user's systems, remove keys belonging to hosts from the `~/.ssh/known_hosts` file if the user has previously logged into the host configured above. When a user logs into the host they should no longer be presented with the warning about the hosts authenticity.
|
||||
|
||||
To test the host certificate, on a client system, ensure the client has set up the global `/etc/ssh/known_hosts` file, as described in xref:proc-Trusting_the_Host_Signing_Key[Trusting the Host Signing Key], and that the server's public key is not in the `~/.ssh/known_hosts` file. Then attempt to log into the server over SSH as a remote user. You should not see a warning about the authenticity of the host. If required, add the [option]`-v` option to the SSH command to see logging information.
|
||||
|
||||
|
|
@ -784,7 +784,7 @@ The default behavior of OpenSSH is that a user is allowed to log in as a remote
|
|||
@cert-authority principals="name1,name2" *.example.com ssh-rsa pass:quotes[_AAAAB5Wm._]
|
||||
----
|
||||
|
||||
* On the server, create an `AuthorizedPrincipalsFile` file, either per user or glabally, and add the principles' names to the file for those users allowed to log in. Then in the `/etc/ssh/sshd_config` file, specify the file using the [command]#AuthorizedPrincipalsFile# directive.
|
||||
* On the server, create an `AuthorizedPrincipalsFile` file, either per user or globally, and add the principles' names to the file for those users allowed to log in. Then in the `/etc/ssh/sshd_config` file, specify the file using the [command]#AuthorizedPrincipalsFile# directive.
|
||||
|
||||
[[proc-Generating_a_User_Certificate]]
|
||||
.Generating a User Certificate
|
||||
|
|
@ -964,7 +964,7 @@ To view a certificate, use the [option]`-L` to list the contents. For example, f
|
|||
permit-user-rc
|
||||
----
|
||||
|
||||
To vew a host certificate:
|
||||
To view a host certificate:
|
||||
|
||||
----
|
||||
~]# ssh-keygen -L -f /etc/ssh/ssh_host_rsa_key-cert.pub
|
||||
|
|
|
|||
Reference in a new issue