SSH RSA key for your router

Sdílet
Vložit
  • čas přidán 6. 11. 2022
  • Access another router via scripts & RSA key pairs!
    help.mikrotik.com/docs/displa...
  • Věda a technologie

Komentáře • 31

  • @ModestTim
    @ModestTim Před rokem +11

    Would be really cool to see the ssh-copy-id command supported to copy a key to the router!

  • @drumaddict89
    @drumaddict89 Před rokem +12

    +1 for support for ecdsa (and maybe also ed25519)
    optional support for authenticator apps would be a KILLER feature out of the box!
    there could also be the possibility to "export" a QR code to the CLI (which ALSO could be used for WIREGUARD peers export - like on a normal shell)

  • @hit-757
    @hit-757 Před rokem +13

    Hi, do you plan to implement ecdsa and ed25519 in RouterOS7?

    • @stormeporm
      @stormeporm Před rokem +4

      That and OpenSSH FIDO devices so -sk keys

  • @MustaMT
    @MustaMT Před rokem +1

    We do like this type of content. However, you guys by now know which product video I'm waiting for 😁 starts with wifi ends with 6e.. I hope these clues are good enough haha

  • @viniciusstucki
    @viniciusstucki Před rokem +1

    Keep doing this great vídeos!!!

  • @SiBex_ovh
    @SiBex_ovh Před rokem +3

    Suggestion: When U2F keys ? When 2FA in VPNs? When WinBox will use U2F/2FA and log connection to log.txt for easier reports ?

  • @JasonsLabVideos
    @JasonsLabVideos Před rokem +1

    Good content !

  • @maigonis.elleris
    @maigonis.elleris Před rokem +1

    I would liek to see videos on automation, like Ansible for example.

  • @alexkota9318
    @alexkota9318 Před 2 měsíci

    i am add ssh-keygen esxi to ssh key mikrotik and can,t open ssh esxi in mikrotik new terminal can you help me ?

  • @Anavllama
    @Anavllama Před rokem

    Okay I use my windows PC to access routers via winbox. Would I use putty to generate key pairs for each MT device and if so, would I only have access to terminal view (CLI) or would I reach winbox??

  • @_Steven_S
    @_Steven_S Před rokem

    I don't remember it being that straightforward the last time I deployed my new key to v6. No trailing whitespace or newlines and a sacrifice to the Mikrotik gods IIRC.

  • @kirksteinklauber260
    @kirksteinklauber260 Před rokem

    very nice!!! thanks for this helpful video. Quick question: is it possible to enforce from a workstation to use a password and ssh key pair to have a kind of dual factor authentication? I mean to access the router is required to have both: the password and the ssh key in order to access it remotely (if any of these 2 conditions are not met, then the user shouldn't be able to access it). Pls advise. Thanks!!

    • @RB01-lite
      @RB01-lite Před rokem

      For SSH it is not possible, but if you are accessing your device remotely it is highly advisable, you use a VPN, which can provide the security you are looking for. OpenVPN for example requires a certificate (same public-private key principles as RSA key) and additionally a password to connect.

  • @wreckedzilla
    @wreckedzilla Před rokem +1

    noice! :p
    Dru best!
    never tried to copy winbox to winbox 😮
    R1 and R2 identities would be 😎

    • @drumaddict89
      @drumaddict89 Před rokem

      WB to WB copy works well on windows and wine(linux)
      never got it running smoothly on macos though.

  • @diegocoirolo2249
    @diegocoirolo2249 Před rokem

    Which Linux distro are use in this video?

  • @sebastian.vargas
    @sebastian.vargas Před rokem +1

    Hi! Question, I load the ssh key but when I want to access the router via ssh it asks me for the password, I put the password and it enters but there will be some way to access without asking for the password

    • @eromerog
      @eromerog Před 3 měsíci

      Me pasa igual, no doy con el problema

  • @j4c0r4m0s
    @j4c0r4m0s Před 28 dny

    Howto keygen for mikrotik v6 in debian 12 ?

  • @HadiSedqi
    @HadiSedqi Před 5 měsíci

    Thanks, how can i login from winbox to ubuntu server by this way? Do you have a learn for this?

    • @mikrotik
      @mikrotik  Před 5 měsíci

      You are probably better off logging in directly into your server, but you can do it through your router too. Just look into SSH keys for ubuntu.

  • @jeyssongome992
    @jeyssongome992 Před rokem

    Deben tener un programa q sean compatibles las ips de los router de casa con los acces point ip estatica estoy a pronto de comprarles una ap clientes. 30 dbi, y probar si deja la intermitencia q tengo no migren toda vidad a 5ghz y dejen mas pmt .. 2 ghz

  • @stevebot
    @stevebot Před rokem

    Littering your private key file all over your devices is not good form and does not scale for management. How about adding agent forwarding as an option? Another nice security feature would be something akin to sudo or Cisco's enable command. Root login directly from the network is another poor security item.

    • @RB01-lite
      @RB01-lite Před rokem

      Private key is only held on one device, public key can be safely shared.

  • @nageebka2013
    @nageebka2013 Před rokem

    نحن نتحدث العربية نحتاج شرح عربي تكرما ملايين يستخدمون مايكروتك

  • @nativeme2143
    @nativeme2143 Před rokem +1

    Unfortunatly useless for me. :( My company uses more secure ed25519 which Mikrotik doesn't support .

    • @tcpipdotcom
      @tcpipdotcom Před rokem +1

      RouterOS 7.7 -> ssh - added support for Ed25519 key exchange;

    • @tcpipdotcom
      @tcpipdotcom Před rokem

      Ok, my bad... This is about ed25519 key exchange., but no way to set up as a user or host key :(