SSH keys

31.12.20

Bitbucket doesn’t like the same key being used to access from 2 different devices.

Set up additional SSH keys

Troubleshoot SSH issues

Trying to do an lpull on new iMac21 fails because bitbucket doesn’t like the public key ported across from old iMac24…

admins-iMac-3:vagrant-2 bill$ lpull
Which site?
chaco
chapelto@poseidon.krystal.co.uk's password: 
  cd private/live.git
  git fetch -v ssh://git@bitbucket.org/TinkerBill/chaco.git master
  git reset --hard FETCH_HEAD
  git clean -dn  
# This does a dry run. Use git clean -df to delete untracked files & directories
[chapelto@poseidon ~]$   cd private/live.git
chaco.git masteron live.git]$   git fetch -v ssh://git@bitbucket.org/TinkerBill/ 
Permission denied (publickey).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

The only public key in .ssh is tinkerbill.pub …

admins-iMac-3:~ bill$ ss
Which site?
chaco
Enter passphrase for key '.ssh/tinkerbill': 
[chapelto@poseidon ~]$ ls -a
.                 .contactemail          .krystal-migration-AAAA  .softaculous
..                .cpanel                .krystal-migration-ZZZZ  .ssh
access-logs       cpbackup-exclude.conf  .lastlogin               ssl
.appdata          .cphorde               logs                     .subaccounts
.bash_history     downloads_tmp          lscache                  tmp
.bash_logout      .DS_Store              mail                     .trash
.bash_profile     etc                    .my.cnf                  var
.bashrc           .gemrc                 perl5                    www
cache             .gitconfig             .pki                     .zshrc
.cagefs           .htpasswds             private
.cl.selector      .jbm                   public_ftp
.cl.selector.bak  .kapps                 public_html
[chapelto@poseidon ~]$ cd .ssh
[chapelto@poseidon .ssh]$ ls -al
total 20
drwx------  2 chapelto chapelto  110 Mar 12  2016 .
drwx--x--x 29 chapelto chapelto 4096 Dec 19 12:37 ..
-rw-r--r--  1 chapelto chapelto  392 Mar 12  2016 authorized_keys
-rw-r--r--  1 chapelto chapelto  392 Mar 12  2016 authorized_keys2
-rw-r--r--  1 chapelto chapelto 2773 Oct 30 13:33 known_hosts
-rw-------  1 chapelto chapelto  392 Mar 12  2016 tinkerbill.pub

Create a new public key tinkerbill1 …

admins-iMac-3:~ bill$ ssh-keygen
Generating public/private rsa key pair.
Enter file in which to save the key (/Users/bill/.ssh/id_rsa): /Users/bill/.ssh/tinkerbill1
Enter passphrase (empty for no passphrase): 
Enter same passphrase again: 
Your identification has been saved in /Users/bill/.ssh/tinkerbill1.
Your public key has been saved in /Users/bill/.ssh/tinkerbill1.pub.
The key fingerprint is:
SHA256:LW78HTcmFytEvOgV4g6srsgVquBfiNgDH5EwKP1yRs8 bill@admins-iMac-3.local
The key's randomart image is:
+---[RSA 2048]----+
|+.               |
|oo...      .     |
|. oo o    . +    |
|  ..+ E. o + o   |
|. .+.   S + + .  |
|.+.o.. + = o   o |
|o.=.... + o + *  |
|oo +.. . . . B . |
|..+....   . .    |
+----[SHA256]-----+
admins-iMac-3:~ bill$ 

Add this new key into the SSH authentication agent for Mac user bill and copy it to the clipboard…

admins-iMac-3:~ bill$ ssh-add ~/.ssh/tinkerbill1
Enter passphrase for /Users/bill/.ssh/tinkerbill1: 
Identity added: /Users/bill/.ssh/tinkerbill1 (bill@admins-iMac-3.local)
admins-iMac-3:~ bill$ cat ~/.ssh/tinkerbill1.pub | pbcopy

Add it as a new key in BitBucket…

This command checks your SSH agent for an SSH key, and then checks if that private key matches a public key for an existing Bitbucket account:

admins-iMac-3:~ bill$ ssh -T git@bitbucket.org
Warning: Permanently added the RSA host key for IP address '104.192.141.1' to the list of known hosts.
logged in as TinkerBill

You can use git or hg to connect to Bitbucket. Shell access is disabled

If you receive a Permission denied (publickey) error, and you’ve already verified that your key is loaded into your SSH agent and into your Bitbucket account, you can get more information about your connection issues with…

admins-iMac-3:~ bill$ ssh -v git@bitbucket.org
OpenSSH_7.9p1, LibreSSL 2.7.3
debug1: Reading configuration data /Users/bill/.ssh/config
debug1: /Users/bill/.ssh/config line 8: Applying options for *
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 20: Applying options for *
debug1: Connecting to bitbucket.org port 22.
debug1: Connection established.
debug1: identity file /Users/bill/.ssh/id_rsa type 0
debug1: identity file /Users/bill/.ssh/id_rsa-cert type -1
debug1: identity file /Users/bill/.ssh/id_dsa type -1
debug1: identity file /Users/bill/.ssh/id_dsa-cert type -1
debug1: identity file /Users/bill/.ssh/id_ecdsa type -1
debug1: identity file /Users/bill/.ssh/id_ecdsa-cert type -1
debug1: identity file /Users/bill/.ssh/id_ed25519 type -1
debug1: identity file /Users/bill/.ssh/id_ed25519-cert type -1
debug1: identity file /Users/bill/.ssh/id_xmss type -1
debug1: identity file /Users/bill/.ssh/id_xmss-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_7.9
debug1: Remote protocol version 2.0, remote software version conker_c123b90d72-dirty conker-3009
debug1: no match: conker_c123b90d72-dirty conker-3009
debug1: Authenticating to bitbucket.org:22 as 'git'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256@libssh.org
debug1: kex: host key algorithm: ssh-rsa
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC:  compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC:  compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ssh-rsa SHA256:zzXQOXSRBEiUtuE8AikJYKwbHaxvSc0ojez9YXaGp1A
debug1: Host 'bitbucket.org' is known and matches the RSA host key.
debug1: Found key in /Users/bill/.ssh/known_hosts:3
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey after 134217728 blocks
debug1: Will attempt key: bill@admins-iMac-3.local RSA SHA256:LW78HTcmFytEvOgV4g6srsgVquBfiNgDH5EwKP1yRs8 agent
debug1: Will attempt key: /Users/bill/.ssh/id_rsa RSA SHA256:9vW3OWHw2KO02IDu7Ys769f5jFpgsw1fX93sXYKPpMs
debug1: Will attempt key: /Users/bill/.ssh/id_dsa 
debug1: Will attempt key: /Users/bill/.ssh/id_ecdsa 
debug1: Will attempt key: /Users/bill/.ssh/id_ed25519 
debug1: Will attempt key: /Users/bill/.ssh/id_xmss 
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Offering public key: bill@admins-iMac-3.local RSA SHA256:LW78HTcmFytEvOgV4g6srsgVquBfiNgDH5EwKP1yRs8 agent
debug1: Server accepts key: bill@admins-iMac-3.local RSA SHA256:LW78HTcmFytEvOgV4g6srsgVquBfiNgDH5EwKP1yRs8 agent
debug1: Authentication succeeded (publickey).
Authenticated to bitbucket.org ([104.192.141.1]:22).
debug1: channel 0: new [client-session]
debug1: Entering interactive session.
debug1: pledge: network
debug1: Requesting authentication agent forwarding.
debug1: Sending environment.
debug1: Sending env LANG = en_GB.UTF-8
PTY allocation request failed on channel 0
debug1: client_input_channel_req: channel 0 rtype exit-status reply 0
logged in as TinkerBill

You can use git or hg to connect to Bitbucket. Shell access is disabled
debug1: channel 0: free: client-session, nchannels 1
Connection to bitbucket.org closed.
Transferred: sent 3052, received 1804 bytes, in 0.2 seconds
Bytes per second: sent 15862.6, received 9376.2
debug1: Exit status 0

Then, trying lpull again, we get..

admins-iMac-3:~ bill$ cdv2
admins-iMac-3:vagrant-2 bill$ lpull
Which site?
chaco
chapelto@poseidon.krystal.co.uk's password: 
  cd private/live.git
  git fetch -v ssh://git@bitbucket.org/TinkerBill/chaco.git master
  git reset --hard FETCH_HEAD
  git clean -dn  
# This does a dry run. Use git clean -df to delete untracked files & directories
[chapelto@poseidon ~]$   cd private/live.git
chaco.git masteron live.git]$   git fetch -v ssh://git@bitbucket.org/TinkerBill/ 
remote: Counting objects: 14, done.
remote: Compressing objects: 100% (14/14), done.
remote: Total 14 (delta 8), reused 0 (delta 0)
Unpacking objects: 100% (14/14), 1.58 KiB | 49.00 KiB/s, done.
From ssh://bitbucket.org/TinkerBill/chaco
 * branch              master     -> FETCH_HEAD
[chapelto@poseidon live.git]$   git reset --hard FETCH_HEAD
HEAD is now at eeab6e7a Merge branch 'develop'
[chapelto@poseidon live.git]$   git clean -dn  
Would remove HEAD
Would remove cms/wordfence-waf.php
Would remove docs/Loanstock_3rd_offer_document_v2.pdf
Would remove docs/Loanstock_3rd_offer_form_v2.docx
Would remove docs/Prospective_member_form.doc
Would remove docs/thankyou_flyer_web.pdf
Would remove logs/
Would remove wp-content/plugins/cookie-law-info/license.txt
Would remove wp-content/plugins/wordfence/vendor/bin/
Would remove wp-content/plugins/wordfence/vendor/composer/038918d7/
Would remove wp-content/plugins/wordfence/vendor/geoip2/geoip2/maxmind-db/
 untracked files & directories# This does a dry run. Use git clean -df to delete 
[chapelto@poseidon live.git]$ packet_write_wait: Connection to 77.72.1.130 port 722: Broken pipe
Saving session...completed.
Deleting expired sessions...none found.

[Process completed]

30/8/21

Connection closed

admins-iMac-3:~ bill$ lpull
Which site?
chaco
chapelto@poseidon.krystal.co.uk's password: 
Connection closed by 77.72.1.130 port 722
Saving session...completed.
Deleting expired sessions...none found.

[Process completed]

If this happens, go to Krystal client area and Disable SSH. Then Enable SSH and try again.

Could not read from remote repository

[chapelto@poseidon live.git]$   git fetch -v ssh://git@bitbucket.org/TinkerBill/chaco.git master
Permission denied (publickey).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

If this happens, add key tinkerbill1 into the SSH authentication agent for Mac user bill.

admins-iMac-3:~ bill$ ssh-add ~/.ssh/tinkerbill1
Enter passphrase for /Users/bill/.ssh/tinkerbill1: 
Identity added: /Users/bill/.ssh/tinkerbill1 (bill@admins-iMac-3.local)