From 97f0e4e50e18323f87753a39f821ba6956e794d0 Mon Sep 17 00:00:00 2001 From: operator-646 Date: Fri, 9 Oct 2026 22:49:00 +0000 Subject: [PATCH] Verify SSH dial-in perms for container 646 - chmod 600 ~/.ssh/authorized_keys (already 600, verified) - sshd listening on :22, reverse tunnel VM 127.0.0.1:2226 -> container:22 up - authorized key present (super@bl); key-auth step belongs to key holder Fixes #213 --- docs/213-ssh-perms-verification.md | 38 ++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 docs/213-ssh-perms-verification.md diff --git a/docs/213-ssh-perms-verification.md b/docs/213-ssh-perms-verification.md new file mode 100644 index 0000000..047422f --- /dev/null +++ b/docs/213-ssh-perms-verification.md @@ -0,0 +1,38 @@ +# Ticket #213 verification — SSH key perms and container dial-in (646) + +Date: 2026-10-09 ~22:50 UTC +Operator: operator-646 (muse-646-patha) +Branch: `dev/646/213-fix-ssh-perms` + +## 1. authorized_keys permissions (port 2226 dial-in) + +- `~/.ssh/authorized_keys` (`/home/hatch/.ssh/authorized_keys`): + - before: `600 root:root` + - ran `chmod 600 ~/.ssh/authorized_keys` per ticket + - after: `600 root:root` (no-op — already correct) +- sshd's requirement (private key file must not be group/world-writable, + ideally 600) is satisfied. `~/.ssh` itself is `700`. + +## 2. Container sshd + +- `sshd` running (pid 2655, listener, 0 of 10-100 startups). +- Listening on `0.0.0.0:22` and `[::]:22`. +- `authorized_keys` holds 1 key: + - `ssh-ed25519 SHA256:UOeqKF5BehWNmEpBSk53Qhz0Jd9aQXbFO0VKe2AVo8c` + (comment `super@bl`) — dial-in identity belongs to super. + +## 3. Reverse tunnel (VM 2226 → container:22) + +- On VM 34.139.37.135 (as dev-operator-646): `127.0.0.1:2226` and + `[::1]:2226` are LISTENING — the reverse tunnel is up. +- Bind is loopback-only (no GatewayPorts), so dial-in must originate + from the VM itself — expected for `ssh -R` forwards. + +## 4. Dial-in path verdict + +Container-side prerequisites are all green: perms 600, sshd listening, +tunnel established, authorized key present. The final key-auth step can +only be completed by the holder of the `super@bl` private key, so no +full loopback auth was attempted from this operator identity. + +Fixes #213