mirror of
https://github.com/curl/curl.git
synced 2026-08-05 08:36:13 +03:00
ssh: improve key file search
For private keys, use the first match from: user-specified key file (if provided), ~/.ssh/id_rsa, ~/.ssh/id_dsa, ./id_rsa, ./id_dsa Note that the previous code only looked for id_dsa files. id_rsa is now generally preferred, as it supports larger key sizes. For public keys, use the user-specified key file, if provided. Otherwise, try to extract the public key from the private key file. This means that passing --pubkey is typically no longer required, and makes the key-handling behavior more like OpenSSH.
This commit is contained in:
parent
b1c4c39c58
commit
fa7d04fed4
3 changed files with 73 additions and 36 deletions
26
docs/MANUAL
26
docs/MANUAL
|
|
@ -41,12 +41,19 @@ SIMPLE USAGE
|
|||
|
||||
Get a file from an SSH server using SFTP:
|
||||
|
||||
curl -u username sftp://shell.example.com/etc/issue
|
||||
curl -u username sftp://example.com/etc/issue
|
||||
|
||||
Get a file from an SSH server using SCP using a private key to authenticate:
|
||||
Get a file from an SSH server using SCP using a private key
|
||||
(not password-protected) to authenticate:
|
||||
|
||||
curl -u username: --key ~/.ssh/id_dsa --pubkey ~/.ssh/id_dsa.pub \
|
||||
scp://shell.example.com/~/personal.txt
|
||||
curl -u username: --key ~/.ssh/id_rsa \
|
||||
scp://example.com/~/file.txt
|
||||
|
||||
Get a file from an SSH server using SCP using a private key
|
||||
(password-protected) to authenticate:
|
||||
|
||||
curl -u username: --key ~/.ssh/id_rsa --pass private_key_password \
|
||||
scp://example.com/~/file.txt
|
||||
|
||||
Get the main page from an IPv6 web server:
|
||||
|
||||
|
|
@ -91,10 +98,13 @@ USING PASSWORDS
|
|||
|
||||
SFTP / SCP
|
||||
|
||||
This is similar to FTP, but you can specify a private key to use instead of
|
||||
a password. Note that the private key may itself be protected by a password
|
||||
that is unrelated to the login password of the remote system. If you
|
||||
provide a private key file you must also provide a public key file.
|
||||
This is similar to FTP, but you can use the --key option to specify a
|
||||
private key to use instead of a password. Note that the private key may
|
||||
itself be protected by a password that is unrelated to the login password
|
||||
of the remote system; this password is specified using the --pass option.
|
||||
Typically, curl will automatically extract the public key from the private
|
||||
key file, but in cases where curl does not have the proper library support,
|
||||
a matching public key file must be specified using the --pubkey option.
|
||||
|
||||
HTTP
|
||||
|
||||
|
|
|
|||
|
|
@ -825,7 +825,8 @@ If this option is used several times, the last one will be used. If
|
|||
unspecified, the option defaults to 60 seconds.
|
||||
.IP "--key <key>"
|
||||
(SSL/SSH) Private key file name. Allows you to provide your private key in this
|
||||
separate file.
|
||||
separate file. For SSH, if not specified, curl tries the following candidates
|
||||
in order: '~/.ssh/id_rsa', '~/.ssh/id_dsa', './id_rsa', './id_dsa'.
|
||||
|
||||
If this option is used several times, the last one will be used.
|
||||
.IP "--key-type <type>"
|
||||
|
|
@ -1283,6 +1284,11 @@ protocol instead of the default HTTP 1.1.
|
|||
separate file.
|
||||
|
||||
If this option is used several times, the last one will be used.
|
||||
|
||||
(As of 7.39.0, curl attempts to automatically extract the public key from the
|
||||
private key file, so passing this option is generally not required. Note that
|
||||
this public key extraction requires libcurl to be linked against a copy of
|
||||
libssh2 1.2.8 or higher that is itself linked against OpenSSL.)
|
||||
.IP "-q"
|
||||
If used as the first parameter on the command line, the \fIcurlrc\fP config
|
||||
file will not be read and used. See the \fI-K, --config\fP for details on the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue