shell_service
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| shell_service [2017/10/26 22:23] – Re-sign SSH host key fingerprints _simon | shell_service [2026/09/27 02:55] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | |||
| - | ====== Usage Guide ====== | ||
| - | |||
| - | [[fez]] and [[torchwood]] run the primary and secondary shell login service for Tardis, externally accessible via < | ||
| - | from a command shell. For those in Windows, you are advised to have a look at [[http:// | ||
| - | |||
| - | You can change the password on your new account using < | ||
| - | |||
| - | For more help in actually getting started using a shell see [[tardis_beginner_tutorials]]. | ||
| - | |||
| - | |||
| - | ====== Shell Server ====== | ||
| - | |||
| - | We run OpenSSH latest authenticated against [[ldap]]. The primary shell login host is [[fez]] which runs Debian Linux (OpenVZ). To log in ssh < | ||
| - | |||
| - | |||
| - | ====== Dumping Screen Sessions, Weechat, Irssi, etc. ====== | ||
| - | |||
| - | While [[fez]] has a full featured install, [[torchwood]] is intentionally nerfed to dissuade people from dumping sessions there. | ||
| - | |||
| - | |||
| - | ====== Reboots ====== | ||
| - | |||
| - | Sometimes a reboot needs to happen, though most try to keep these as infrequent as possible. | ||
| - | |||
| - | Some reasons (not exhaustive) a reboot may need to occur on a shell server: | ||
| - | * Critical Security Patches | ||
| - | * Kernel Updates | ||
| - | * [[# | ||
| - | * ' | ||
| - | * Hardware changes (in the case of [[torchwood]]) | ||
| - | |||
| - | If you need to perform a reboot of a shell server, it's usually nice to let others know that you're going to do so. | ||
| - | |||
| - | There are a few ways people do this - some will just use the scheduled reboot functionality in the < | ||
| - | |||
| - | Another strategy that some use is to edit < | ||
| - | |||
| - | Also useful here is the < | ||
| - | |||
| - | Ultimately, it is up to your own judgement on if you *should* reboot a shell server, and if you are going to, how much you let people know in advance. | ||
| - | |||
| - | Oh, one more thing... Remember if you're rebooting a machine from Proxmox over an SSH tunnel, and that tunnel lands on the machine you're rebooting, you will lose connection to proxmox. This is one of the reasons we have two shell servers. | ||
| - | |||
| - | |||
| - | ===== Unattended Upgrades ===== | ||
| - | |||
| - | It emails < | ||
| - | | ||
| - | Unattended upgrade returned: None | ||
| - | | ||
| - | Warning: A reboot is required to complete this upgrade. | ||
| - | | ||
| - | Packages that attempted to upgrade: | ||
| - | | ||
| - | Packages with upgradable origin but kept back: | ||
| - | | ||
| - | | ||
| - | Unattended-upgrades log: | ||
| - | Initial blacklisted packages: | ||
| - | Initial whitelisted packages: | ||
| - | Starting unattended upgrades script | ||
| - | Allowed origins are: [' | ||
| - | Packages that will be upgraded: | ||
| - | |||
| - | |||
| - | It is up to your own judgement if the package mentioned really needs a reboot, or if it can wait until the next thing to come up that requires a reboot. This will likely be because of a Debian Security advisory, so go check [[https:// | ||
| - | |||
| - | |||
| - | ====== SSH Key Fingerprints ====== | ||
| - | |||
| - | | ||
| - | -----BEGIN PGP SIGNED MESSAGE----- | ||
| - | Hash: SHA512 | ||
| - | | ||
| - | ssh.tardis.ed.ac.uk SSH host key fingerprints | ||
| - | | ||
| - | +---[DSA 1024]----+ | ||
| - | | . ++.+.Eo | ||
| - | | o o=..+ | | ||
| - | | . oo. = | ||
| - | | .. o.o + | | ||
| - | | .o+. SO | ||
| - | | o.=o+.* . | | ||
| - | | . =o=oo o . . | ||
| - | | o.==. . . + | | ||
| - | | ..o..o | ||
| - | +----[SHA256]-----+ | ||
| - | | ||
| - | +---[ECDSA 256]---+ | ||
| - | | | ||
| - | | . o..+ = . | | ||
| - | | . +.o.E . . | SHA1 = 76: | ||
| - | | | ||
| - | | + .oS . o | SHA256 = / | ||
| - | | o o.=++.+ | ||
| - | | =.oo=++ | ||
| - | | | ||
| - | | ooo. . | ||
| - | +----[SHA256]-----+ | ||
| - | | ||
| - | +---[RSA 2048]----+ | ||
| - | | | ||
| - | | . .o*| | ||
| - | | .o.*=| | ||
| - | | oO B| | ||
| - | | S o.++.++| | ||
| - | | E* Xoo o.| | ||
| - | | ..X * . .| SSHFP = 1 1 EFDA27860463131F605F17BD13FE26F99DE9B27F | ||
| - | | o+== o. | | ||
| - | | | ||
| - | +----[SHA256]-----+ | ||
| - | | ||
| - | -----BEGIN PGP SIGNATURE----- | ||
| - | Version: GnuPG v2 | ||
| - | | ||
| - | iQIcBAEBCgAGBQJZ8mAQAAoJELr// | ||
| - | kJebFYvwl72YHuShifNNAidOK5wp8VLWrAHg+lLQHZ8trghCsxrMxhjHBUhMbMEZ | ||
| - | pWk74uiswwv+WWwotO26dRMwRo12HN813UZRfjp+Gyqu5b5WOdgOnG3qN/ | ||
| - | j99UnCuZ39WpeXR8xGGWcAFF+5OT7aRugjtGLBUM/ | ||
| - | s16XeQN2pcAS+EdlWERPniBNOg+3sON+LSkBvFWLEA0dqUoDEjsXJOAnFKRWZ4hA | ||
| - | ad/ | ||
| - | 1qtRsgk/ | ||
| - | d2aq8oD+3TgAqUjY8Ct41u5DxGVyGlSHVoi5nLOkkNvYOqYlsO36GB6pQniLTOU3 | ||
| - | zo3uQSBXLVwpujhBlZSIM6fSBUvkGSMIBz3uaYkNhJXPkdqAs+LH2f58+3/ | ||
| - | AAo180I8gLoRoWi7lMX4YcYJp1rXERI8qhISs+soLIKFp8I/ | ||
| - | MjTo88HzcY69TfeBkXT35Q3zYsGdAcPh58T3C+du9Dnc9QW9mCwcebcstzAa+RIz | ||
| - | V5Lq1rYwxvfPDUYoAvnN | ||
| - | =9eyV | ||
| - | -----END PGP SIGNATURE----- | ||
| - | |||
| - | |||
| - | < | ||
| - | -----BEGIN PGP SIGNED MESSAGE----- | ||
| - | Hash: SHA512 | ||
| - | |||
| - | ssh1.tardis.ed.ac.uk SSH host key fingerprints | ||
| - | |||
| - | +---[DSA 1024]----+ | ||
| - | | o. . | ||
| - | |. .o .o+ o | | ||
| - | |. + + o o.B | SHA1 = 53: | ||
| - | | . O = O . | | ||
| - | | + o o S * | SHA256 = QiYkjN7Zn1OWa2rNtAdRhssx5IT/ | ||
| - | | E o . = X o | | ||
| - | |. . o O B | SSHFP = 2 1 534987C029091CAF50BE6B52E1EAB9BA4B0C116A | ||
| - | | . . o + + o | | ||
| - | | o o | ||
| - | +----[SHA256]-----+ | ||
| - | |||
| - | +---[ECDSA 256]---+ | ||
| - | | *O+o. | MD5 = 7f: | ||
| - | | oO=oE | | ||
| - | | Oo=.. | SHA1 = 49: | ||
| - | | | ||
| - | | ..B.S.= | ||
| - | | . ..o++ + o | | ||
| - | | .... = . + . | SSHFP = 3 1 494CC18F50C9075694FAB58E49BA2E14B0E83723 | ||
| - | | oo. + | | ||
| - | | ... . | ||
| - | +----[SHA256]-----+ | ||
| - | |||
| - | +---[RSA 2048]----+ | ||
| - | | o o+XO**B| | ||
| - | | o o.%.*+=.| | ||
| - | | . * * * o| SHA1 = 34: | ||
| - | | = E.oo| | ||
| - | | S . + +=o| SHA256 = dwUOYt5TiXHUwaDlFDpXRq87QNzpURwVIXlvGt+9IRw | ||
| - | | . . +.o+| | ||
| - | | + o| SSHFP = 1 1 3423FE5A2F40744606785EC5CD646206A57A5310 | ||
| - | | o | | ||
| - | | | ||
| - | +----[SHA256]-----+ | ||
| - | |||
| - | -----BEGIN PGP SIGNATURE----- | ||
| - | Version: GnuPG v2 | ||
| - | |||
| - | iQIcBAEBCgAGBQJZ8l// | ||
| - | rGbkw+M+JGZKqLO47a5tWA/ | ||
| - | fei6S1VImmuJcAGwdnhXfXdus54+7iK5u+iNAQUMZAOE9r4tWlyhQYqmqs1Ui1ns | ||
| - | lMbfXKnlysIih1CK0CFzoByXRNBxuwzns65yI/ | ||
| - | +oeSpJ3nVix6cAhrbfUHDLj3yYAruCmpDpexEiZt63350j0iF4k/ | ||
| - | hJv7U78qnVIl8MJ1YZI6CYNVtKw45VX13aXDoCUJ/ | ||
| - | OkRQg8H95hOWDXi/ | ||
| - | UJyjnD+7A+RaH0xd8azkI9iS+6gqpI+QPQmBvIfevQP6U7K1Pa+FHrSRCpWWB/ | ||
| - | +SkZbyrebgiK7TmBzMu0vfM1cB9s9DOdk/ | ||
| - | r7vcYHPqueqovRgA9VyeSLmt+pzliRmyLP/ | ||
| - | OjV/ | ||
| - | htXfJDCU3U2UcTGg3+Yy | ||
| - | =EM71 | ||
| - | -----END PGP SIGNATURE----- | ||
| - | </ | ||
| - | |||
| - | |||
| - | |||
shell_service.1509056616.txt.gz · Last modified: (external edit)
