From: Gyepi SAM Date: 2009-10-23T06:40:40+09:00 Subject: Re: Using SHA1 Digested Passwords for SSH connection Hi Joe, I can't speak for the Windows side, but on the Unix side, you could generate public/private keys and connect with those. You could manage the keys through ssh agent. All of this is supported by Net/SSH, with the only issue being that the private key is generally specified as a path to a file and I am not sure if Net/SSH allows the possibility to present the key as data (read from the database). You could always write a copy of the data to a file, ask ssh-agent to read it, then delete the file; but that seems inelegant. Regards -Gyepi On Fri, Oct 23, 2009 at 02:21:39AM +0900, Joe Martin wrote: > Hello all. > For testing, I have been inputting some various user credentials into a > database. The passwords are hashed (digested) with the SHA1 algorithm. > I have a script set up to read these passwords, and use them for > credentials for connecting to other machines to perform actions on each. > > As you can imagine, passwords in clear-text connect just fine, but I'm > wondering if its possible to force the host to verify the digested > password, and allow the connection if the password matches the host's > stored password. > > I'm using Net/SSH for connections to UNIX hosts, and WIN32OLE for > WMI/Registry connections on Windows. > > If this is not possible how would I accomplish this? Basically, I want > to store passwords in a database in a secure fashion, read these > passwords and use them to connect to remote hosts. Is there a way to > accomplish this, or am I going about it the wrong way? > > This is my first stab at security, so I'm slowly learning as I go along. > Thanks!