StarCluster - Mailing List Archive

Re: apache user remotely ssh to starcluster

From: Justin Riley <no email>
Date: Mon, 31 Oct 2011 10:28:32 -0400

Hash: SHA1

Hi Leo,

If you try running your ssh command by first logging in interactively
as the apache user and then running the command you will most likely
discover that ssh is prompting you to verify the host key. This is
because it's the first time you're connecting to the StarCluster head
node from your apache server:

$ su - apache -s /bin/sh
$ ssh -i /home/ec2-user/.ssh/key_file.rsa
The authenticity of host ' (' can't be
RSA key fingerprint is 3f:1b:f4:bd:c5:aa:c1:1f:bf:4e:2e:cf:53:fa:d8:59.
Are you sure you want to continue connecting (yes/no)?

If you wish to accept the host key and connect in a one-liner you'll
need to pass "-o StrictHostKeyChecking=no" to your ssh command to
avoid being prompted:

$ ssh -i /home/ec2-user/.ssh/key_file.rsa -o StrictHostKeyChecking=no \

You should really only do this the *first* time you connect otherwise
you're subject to man in the middle, etc.



On 10/27/2011 12:55 AM, liang cheng wrote:
> Hi,
> I'm experimenting how to allow apache user to run a script sitting
> on the star cluster from a front end EC2 instance.
> At the front end server, when I tried to login as apache user to
> run the script, I got this:
> sudo su -s /bin/sh apache -c "ssh -i
> /home/ec2-user/.ssh/key_file.rsa
>" Warning: Identity file
> /home/ec2-user/.ssh/key_file.rsa not accessible: Permission
> denied. Could not create directory '/var/www/.ssh'. Host key
> verification failed.
> Then I tried to move the rsa file to a directory that apache user
> has the permission to read. But when running the line below. I
> still get error message:
> sudo su -s /bin/sh apache -c "ssh -i
> /home/ec2-user/.ssh/key_file.rsa
> Host key verification failed.
> Can someone help me ? Does star cluster natively support this kind
> of application ? Ideally the apache user should be able to run
> scrip on star cluster and get the output of the script, all from
> the front end apache server machine.
> Thanks, -Leo _______________________________________________
> StarCluster mailing list

Version: GnuPG v2.0.17 (GNU/Linux)
Comment: Using GnuPG with Mozilla -

Received on Mon Oct 31 2011 - 10:28:35 EDT
This archive was generated by hypermail 2.3.0.


Sort all by: