Bug 2170031

Summary: [RFE]Password protected SSH keys for remote execution.
Product: Red Hat Satellite Reporter: Vedashree Deshpande <vdeshpan>
Component: DocumentationAssignee: satellite6-bugs <satellite6-bugs>
Documentation sub component: default QA Contact: Peter Ondrejka <pondrejk>
Status: NEW --- Docs Contact:
Severity: medium    
Priority: unspecified CC: aruzicka, dsinglet
Version: 6.10.0Keywords: FutureFeature
Target Milestone: Unspecified   
Target Release: Unused   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Vedashree Deshpande 2023-02-15 12:52:02 UTC
Description of problem:

Customer want to increase the security level. Right now satellite is using one (non password protected) ssh key to run remote jobs on all of our hosts. They would like to use password protected ssh key, so even after it is somehow extracted from the satellite, the person would have to know the password to use it.


Version-Release number of selected component (if applicable):
Satellite 6.10 onward


Actual results:
existing SSH key do not have passwords to access them

Expected results:
Password protected SSH key for security reasons. 

Additional info:

Comment 2 Adam Ruzicka 2023-02-15 12:54:48 UTC
Well, they can do this themselves. They either can replace the key with their own or just add an passphrase to an already existing key.

Comment 3 Adam Ruzicka 2023-02-16 10:47:17 UTC
Is it a future feature though? It is possible manually right now. Yes, we could document it and we could possibly make the installer generate passphrase protected keys, but almost surely not by default.

Comment 4 Vedashree Deshpande 2023-02-16 11:02:01 UTC
Sure Adam. I have suggested a way to achieve it to the customer. Please share if you have a document currently or where we can incorporate this?

Comment 5 Adam Ruzicka 2023-02-16 11:19:35 UTC
I don't really have anything. It could either end up being a KCS or go into the proper docs