Security issue with master password and ssh key [1]
Security issue with master password and ssh key
Monday, December 1, 2014 1:56 PM - Grégoire
Hello,
I use Xshell 5 build 0446 and I have set a password to protect my sessions.
But here my surprise as for once, I did not fill the master password to see that the sessions remain available.
Second surprise, as I use ssh key only to connect to my servers, I can freely connect without entering the master password.
Ok I should maybe set a passphrase to my private key but well, I thought that the master password encrypt also my private key...
Thanks any way for your great tool !!!
Program Ver. : Xshell 5
I use Xshell 5 build 0446 and I have set a password to protect my sessions.
But here my surprise as for once, I did not fill the master password to see that the sessions remain available.
Second surprise, as I use ssh key only to connect to my servers, I can freely connect without entering the master password.
Ok I should maybe set a passphrase to my private key but well, I thought that the master password encrypt also my private key...
Thanks any way for your great tool !!!
Program Ver. : Xshell 5
Re: Security issue with master password and ssh key
Tuesday, December 2, 2014 12:38 AM - Support
Thank you for using Xshell!
We can make Xshell to encrypt blank passphrase but this will make some user unhappy since they probably have used blank password in order to save the hassle of entering the passphrase. So, using a blank passphrase and master password contradicts each others purpose.
Can you explain in little more detail what you mean by "I did not fill the master password to see that the sessions remain available."
---
Technical Support
We can make Xshell to encrypt blank passphrase but this will make some user unhappy since they probably have used blank password in order to save the hassle of entering the passphrase. So, using a blank passphrase and master password contradicts each others purpose.
Can you explain in little more detail what you mean by "I did not fill the master password to see that the sessions remain available."
---
Technical Support
Previous views: 986