Accessing Jails Using SSH
Describes how to access Jails using SSH in FreeCORE.
Each jail has its own accounts, SSH configuration, host keys, and network address. Enabling SSH on the FreeCORE host does not enable it inside a jail.
Configure SSH Inside the Jail
Go to Jails, expand the jail, and click Start. When its state is up, click Shell.
Create a non-root account and enable the jail's SSH daemon:
adduser
sysrc sshd_enable=YES
service sshd start
The first start generates the jail's SSH host keys. Configure the account with an SSH public key when possible; enable password authentication only when it is required by the client and appropriate for the network.
Connect and Verify the Host Key
From another system, connect to the jail address:
ssh username@jail-address
Verify the host-key fingerprint through a trusted path before accepting it. A changed fingerprint can mean that the jail was rebuilt or that the connection is being intercepted.
Grant administrative access only when the account needs it. Membership in the jail's wheel group permits use of su when the jail root account has a password; it does not grant any privilege on the FreeCORE host.
Repeat this setup for each jail that needs SSH. To open a jail console without running an SSH service, use the jail's Shell action in the web interface.