39 lines
1.4 KiB
Markdown
39 lines
1.4 KiB
Markdown
|
|
# Ticket #213 verification — SSH key perms and container dial-in (646)
|
||
|
|
|
||
|
|
Date: 2026-10-09 ~22:50 UTC
|
||
|
|
Operator: operator-646 (muse-646-patha)
|
||
|
|
Branch: `dev/646/213-fix-ssh-perms`
|
||
|
|
|
||
|
|
## 1. authorized_keys permissions (port 2226 dial-in)
|
||
|
|
|
||
|
|
- `~/.ssh/authorized_keys` (`/home/hatch/.ssh/authorized_keys`):
|
||
|
|
- before: `600 root:root`
|
||
|
|
- ran `chmod 600 ~/.ssh/authorized_keys` per ticket
|
||
|
|
- after: `600 root:root` (no-op — already correct)
|
||
|
|
- sshd's requirement (private key file must not be group/world-writable,
|
||
|
|
ideally 600) is satisfied. `~/.ssh` itself is `700`.
|
||
|
|
|
||
|
|
## 2. Container sshd
|
||
|
|
|
||
|
|
- `sshd` running (pid 2655, listener, 0 of 10-100 startups).
|
||
|
|
- Listening on `0.0.0.0:22` and `[::]:22`.
|
||
|
|
- `authorized_keys` holds 1 key:
|
||
|
|
- `ssh-ed25519 SHA256:UOeqKF5BehWNmEpBSk53Qhz0Jd9aQXbFO0VKe2AVo8c`
|
||
|
|
(comment `super@bl`) — dial-in identity belongs to super.
|
||
|
|
|
||
|
|
## 3. Reverse tunnel (VM 2226 → container:22)
|
||
|
|
|
||
|
|
- On VM 34.139.37.135 (as dev-operator-646): `127.0.0.1:2226` and
|
||
|
|
`[::1]:2226` are LISTENING — the reverse tunnel is up.
|
||
|
|
- Bind is loopback-only (no GatewayPorts), so dial-in must originate
|
||
|
|
from the VM itself — expected for `ssh -R` forwards.
|
||
|
|
|
||
|
|
## 4. Dial-in path verdict
|
||
|
|
|
||
|
|
Container-side prerequisites are all green: perms 600, sshd listening,
|
||
|
|
tunnel established, authorized key present. The final key-auth step can
|
||
|
|
only be completed by the holder of the `super@bl` private key, so no
|
||
|
|
full loopback auth was attempted from this operator identity.
|
||
|
|
|
||
|
|
Fixes #213
|