On Tue, 09/19 10:18, Eric Blake wrote:
> On 09/19/2017 02:27 AM, Fam Zheng wrote:
> > This will be used by setup test user ssh.
> > 
> > Signed-off-by: Fam Zheng <f...@redhat.com>
> > ---
> >  tests/keys/README     |  6 ++++++
> >  tests/keys/id_rsa     | 27 +++++++++++++++++++++++++++
> >  tests/keys/id_rsa.pub |  1 +
> >  3 files changed, 34 insertions(+)
> >  create mode 100644 tests/keys/README
> >  create mode 100644 tests/keys/id_rsa
> >  create mode 100644 tests/keys/id_rsa.pub
> > 
> > diff --git a/tests/keys/README b/tests/keys/README
> > new file mode 100644
> > index 0000000000..f381ac0698
> > --- /dev/null
> > +++ b/tests/keys/README
> > @@ -0,0 +1,6 @@
> > +This folder contains a well-known key pair used in QEMU tests.
> 
> s/key/ssh key/ ?

Yup.

> 
> > +
> > +Some guests require the key to exist prior to provisioning the guest; also,
> > +reusing a pre-built key avoids consuming entropy every time the testsuite 
> > is
> > +run.  Because the private key is well-known, care must be taken to use the 
> > key
> > +ONLY in situations that cannot be compromised by external network clients.
> 
> Thanks; that helps.
> 
> > +++ b/tests/keys/id_rsa.pub
> > @@ -0,0 +1 @@
> > +ssh-rsa 
> > AAAAB3NzaC1yc2EAAAADAQABAAABAQCikC46WYtXotUd0UGPz9547Aj0KqC4gk+nt4BBJm86IHgCD9FygSGX9EFutXlhz9KZIPg9Okk7+IzXRHCWI2MNvhrcjyrezKREm71z08j9iwfxY3340fY2Mo+0khwpO7bzsgzkljHIHqcOg7MgttPInVMNH/EfqpgR8EDKJuWCB2Ny+EBFN/3dAiff0X/EvKle9PUrY70EkSycnyURS8HZReEqj8lN9J5kXzA8F6jBo/0Q42Ttv6e4k5YcaDrwmLrBWLra2PCXZLNyHqXEiFkGmdXtA1Eox9gc/p4jIXim6xrPNmpN6WyrrEjaCF5xYvNv8wXkD6uSWwbHYU24lIAn
> >  qemu-test
> 
> Let's make the comment even longer (I think you can use 'ssh-keygen -C
> "some useful comment"', but
> https://serverfault.com/questions/442933/add-comment-to-existing-ssh-public-key
> has more information): maybe along the lines of:
> 
> ssh-rsa AAAAB...IAn well-known key for qemu-test, do not use on any
> machine exposed to an external network

OK.

Reply via email to