You generated an SSH key pair on your laptop and want passwordless logins to the server web01. Which file has to change, and on which machine?
LPIC-1 Exam 102-500, objective 110. Security easy
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct Copy the private key ~/.ssh/id_ed25519 from the laptop into ~/.ssh/authorized_keys on web01.
Wrong, and a serious mistake. A private key never leaves the machine that generated it, and authorized_keys holds public keys only.
Not correct Append web01's host key to ~/.ssh/authorized_keys on the laptop.
Wrong. The server's host key is recorded by the client in ~/.ssh/known_hosts, and it exists so the client can verify the server. It plays no part in authenticating you to the server.
Correct Append the public key ~/.ssh/id_ed25519.pub from the laptop to ~/.ssh/authorized_keys in your account on web01.
Correct. authorized_keys lives on the machine you log in to and lists the public keys permitted to authenticate as that account. ssh-copy-id automates exactly this append.
Not correct Append the laptop's public key to ~/.ssh/known_hosts on web01.
Wrong. known_hosts is the client-side record of the host keys of servers already contacted; it is consulted to detect a changed or spoofed server, never to authorise a user.
Why
Remember which file lives where. authorized_keys is on the server and answers 'which users may log in as this account'. known_hosts is on the client and answers 'have I seen this server's host key before'. The server's own host key pairs are in /etc/ssh/ssh_host_*_key, and it is their fingerprint you are shown on a first connection. `ssh-copy-id user@web01` does the append and fixes the permissions in one step.
Where this comes from
- Cited
- LPI exam objective 110.3
- What it says
- Configure public key authentication with authorized_keys and understand known_hosts.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked