From: Aaron Turner Date: 2009-10-23T06:02:23+09:00 Subject: Re: Using SHA1 Digested Passwords for SSH connection On Thu, Oct 22, 2009 at 10:21 AM, Joe Martin wrote: > Hello all. > For testing, I have been inputting some various user credentials into a > database.  The passwords are hashed (digested) with the SHA1 algorithm. > I have a script set up to read these passwords, and use them for > credentials for connecting to other machines to perform actions on each. > > As you can imagine, passwords in clear-text connect just fine, but I'm > wondering if its possible to force the host to verify the digested > password, and allow the connection if the password matches the host's > stored password. Unfortunately, it isn't possible to send the remote host the SHA1'd password and have them validate it that way. > I'm using Net/SSH for connections to UNIX hosts, and WIN32OLE for > WMI/Registry connections on Windows. > > If this is not possible how would I accomplish this?  Basically, I want > to store passwords in a database in a secure fashion, read these > passwords and use them to connect to remote hosts.  Is there a way to > accomplish this, or am I going about it the wrong way? This is a hard/common problem that people have. Generally speaking the "correct" answer is to design your system so you don't need to store user passwords in the database and then forward the passwords to a remote system for authentication. There really isn't a secure way to solve the problem in this manner. -- Aaron Turner http://synfin.net/ http://tcpreplay.synfin.net/ - Pcap editing and replay tools for Unix & Windows Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety. -- Benjamin Franklin