[{"id":1771162,"web_url":"http://patchwork.ozlabs.org/comment/1771162/","msgid":"<8760ceenfi.fsf@linaro.org>","list_archive_url":null,"date":"2017-09-19T15:08:17","subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","submitter":{"id":39532,"url":"http://patchwork.ozlabs.org/api/people/39532/","name":"Alex Bennée","email":"alex.bennee@linaro.org"},"content":"Fam Zheng <famz@redhat.com> writes:\n\n> This will be used by setup test user ssh.\n>\n> Signed-off-by: Fam Zheng <famz@redhat.com>\n\nReviewed-by: Alex Bennée <alex.bennee@linaro.org>\n\n> ---\n>  tests/keys/README     |  6 ++++++\n>  tests/keys/id_rsa     | 27 +++++++++++++++++++++++++++\n>  tests/keys/id_rsa.pub |  1 +\n>  3 files changed, 34 insertions(+)\n>  create mode 100644 tests/keys/README\n>  create mode 100644 tests/keys/id_rsa\n>  create mode 100644 tests/keys/id_rsa.pub\n>\n> diff --git a/tests/keys/README b/tests/keys/README\n> new file mode 100644\n> index 0000000000..f381ac0698\n> --- /dev/null\n> +++ b/tests/keys/README\n> @@ -0,0 +1,6 @@\n> +This folder contains a well-known key pair used in QEMU tests.\n> +\n> +Some guests require the key to exist prior to provisioning the guest; also,\n> +reusing a pre-built key avoids consuming entropy every time the testsuite is\n> +run.  Because the private key is well-known, care must be taken to use the key\n> +ONLY in situations that cannot be compromised by external network clients.\n> diff --git a/tests/keys/id_rsa b/tests/keys/id_rsa\n> new file mode 100644\n> index 0000000000..2933eac3db\n> --- /dev/null\n> +++ b/tests/keys/id_rsa\n> @@ -0,0 +1,27 @@\n> +-----BEGIN RSA PRIVATE KEY-----\n> +MIIEowIBAAKCAQEAopAuOlmLV6LVHdFBj8/eeOwI9CqguIJPp7eAQSZvOiB4Ag/R\n> +coEhl/RBbrV5Yc/SmSD4PTpJO/iM10RwliNjDb4a3I8q3sykRJu9c9PI/YsH8WN9\n> ++NH2NjKPtJIcKTu287IM5JYxyB6nDoOzILbTyJ1TDR/xH6qYEfBAyiblggdjcvhA\n> +RTf93QIn39F/xLypXvT1K2O9BJEsnJ8lEUvB2UXhKo/JTfSeZF8wPBeowaP9EONk\n> +7b+nuJOWHGg68Ji6wVi62tjwl2Szch6lxIhZBpnV7QNRKMfYHP6eIyF4pusazzZq\n> +Telsq6xI2ghecWLzb/MF5A+rklsGx2FNuJSAJwIDAQABAoIBAHHi4o/8VZNivz0x\n> +cWXn8erzKV6tUoWQvW85Lj/2RiwJvSlsnYZDkx5af1CpEE2HA/pFT8PNRqsd+MWC\n> +7AEy710cVsM4BYerBFYQaYxwzblaoojo88LSjVPw3h5Z0iLM8+IMVd36nwuc9dpE\n> +R8TecMZ1+U4Tl6BgqkK+9xToZRdPKdjS8L5MoFhGN+xY0vRbbJbGaV9Q0IHxLBkB\n> +rEBV7T1mUynneCHRUQlJQEwJmKpT8MH3IjsUXlG5YvnuuvcQJSNTaW2iDLxuOKp8\n> +cxW8+qL88zpb1D5dppoIu6rlrugN0azSq70ruFJQPc/A8GQrDKoGgRQiagxNY3u+\n> +vHZzXlECgYEA0dKO3gfkSxsDBb94sQwskMScqLhcKhztEa8kPxTx6Yqh+x8/scx3\n> +XhJyOt669P8U1v8a/2Al+s81oZzzfQSzO1Q7gEwSrgBcRMSIoRBUw9uYcy02ngb/\n> +j/ng3DGivfJztjjiSJwb46FHkJ2JR8mF2UisC6UMXk3NgFY/3vWQx78CgYEAxlcG\n> +T3hfSWSmTgKRczMJuHQOX9ULfTBIqwP5VqkkkiavzigGRirzb5lgnmuTSPTpF0LB\n> +XVPjR2M4q+7gzP0Dca3pocrvLEoxjwIKnCbYKnyyvnUoE9qHv4Kr+vDbgWpa2LXG\n> +JbLmE7tgTCIp20jOPPT4xuDvlbzQZBJ5qCQSoZkCgYEAgrotSSihlCnAOFSTXbu4\n> +CHp3IKe8xIBBNENq0eK61kcJpOxTQvOha3sSsJsU4JAM6+cFaxb8kseHIqonCj1j\n> +bhOM/uJmwQJ4el/4wGDsbxriYOBKpyq1D38gGhDS1IW6kk3erl6VAb36WJ/OaGum\n> +eTpN9vNeQWM4Jj2WjdNx4QECgYAwTdd6mU1TmZCrJRL5ZG+0nYc2rbMrnQvFoqUi\n> +BvWiJovggHzur90zy73tNzPaq9Ls2FQxf5G1vCN8NCRJqEEjeYCR59OSDMu/EXc2\n> +CnvQ9SevHOdS1oEDEjcCWZCMFzPi3XpRih1gptzQDe31uuiHjf3cqcGPzTlPdfRt\n> +D8P92QKBgC4UaBvIRwREVJsdZzpIzm224Bpe8LOmA7DeTnjlT0b3lkGiBJ36/Q0p\n> +VhYh/6cjX4/iuIs7gJbGon7B+YPB8scmOi3fj0+nkJAONue1mMfBNkba6qQTc6Y2\n> +5mEKw2/O7/JpND7ucU3OK9plcw/qnrWDgHxl0Iz95+OzUIIagxne\n> +-----END RSA PRIVATE KEY-----\n> diff --git a/tests/keys/id_rsa.pub b/tests/keys/id_rsa.pub\n> new file mode 100644\n> index 0000000000..d9888e312f\n> --- /dev/null\n> +++ b/tests/keys/id_rsa.pub\n> @@ -0,0 +1 @@\n> +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCikC46WYtXotUd0UGPz9547Aj0KqC4gk+nt4BBJm86IHgCD9FygSGX9EFutXlhz9KZIPg9Okk7+IzXRHCWI2MNvhrcjyrezKREm71z08j9iwfxY3340fY2Mo+0khwpO7bzsgzkljHIHqcOg7MgttPInVMNH/EfqpgR8EDKJuWCB2Ny+EBFN/3dAiff0X/EvKle9PUrY70EkSycnyURS8HZReEqj8lN9J5kXzA8F6jBo/0Q42Ttv6e4k5YcaDrwmLrBWLra2PCXZLNyHqXEiFkGmdXtA1Eox9gc/p4jIXim6xrPNmpN6WyrrEjaCF5xYvNv8wXkD6uSWwbHYU24lIAn qemu-test\n\n\n--\nAlex Bennée","headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=nongnu.org\n\t(client-ip=2001:4830:134:3::11; helo=lists.gnu.org;\n\tenvelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n\treceiver=<UNKNOWN>)","ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=linaro.org header.i=@linaro.org\n\theader.b=\"Kab3QcAX\"; dkim-atps=neutral"],"Received":["from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11])\n\t(using TLSv1 with cipher AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xxRwM4TgDz9sBZ\n\tfor <incoming@patchwork.ozlabs.org>;\n\tWed, 20 Sep 2017 01:42:59 +1000 (AEST)","from localhost ([::1]:43641 helo=lists.gnu.org)\n\tby lists.gnu.org with esmtp (Exim 4.71) (envelope-from\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>)\n\tid 1duKfp-0000PK-NN\n\tfor incoming@patchwork.ozlabs.org; Tue, 19 Sep 2017 11:42:57 -0400","from eggs.gnu.org ([2001:4830:134:3::10]:52456)\n\tby lists.gnu.org with esmtp (Exim 4.71)\n\t(envelope-from <alex.bennee@linaro.org>) id 1duK8N-00046Z-1S\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:08:24 -0400","from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71)\n\t(envelope-from <alex.bennee@linaro.org>) id 1duK8K-0007Qh-8R\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:08:23 -0400","from mail-wr0-x22d.google.com ([2a00:1450:400c:c0c::22d]:45925)\n\tby eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16)\n\t(Exim 4.71) (envelope-from <alex.bennee@linaro.org>)\n\tid 1duK8K-0007OU-2n\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:08:20 -0400","by mail-wr0-x22d.google.com with SMTP id m18so276774wrm.2\n\tfor <qemu-devel@nongnu.org>; Tue, 19 Sep 2017 08:08:20 -0700 (PDT)","from zen.linaro.local ([81.128.185.34])\n\tby smtp.gmail.com with ESMTPSA id\n\t30sm9533348wry.34.2017.09.19.08.08.16\n\t(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);\n\tTue, 19 Sep 2017 08:08:16 -0700 (PDT)","from zen (localhost [127.0.0.1])\n\tby zen.linaro.local (Postfix) with ESMTPS id 498E93E02BD;\n\tTue, 19 Sep 2017 16:08:17 +0100 (BST)"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google;\n\th=references:user-agent:from:to:cc:subject:in-reply-to:date\n\t:message-id:mime-version:content-transfer-encoding;\n\tbh=cYoyCR6hs1ofJfqPAgcMJBvuTA7MV1vSXxD2mBxV3gM=;\n\tb=Kab3QcAX4q/9mbaC4DvMza5dtPccmihhip5IN4L35HSaocX4ftrEQz8S1PhH5Q3q8y\n\tHtrxClmM+I3qR8OABBCtD2hlB2T6gwMG/pqEjHJHexiVhNS7p7+YgRATzuujr6pO8EvP\n\tt45j5o2yLZCQSO3a2ZGWxiU1+BIcDIWWLvgrI=","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:references:user-agent:from:to:cc:subject\n\t:in-reply-to:date:message-id:mime-version:content-transfer-encoding; \n\tbh=cYoyCR6hs1ofJfqPAgcMJBvuTA7MV1vSXxD2mBxV3gM=;\n\tb=gr7fsrukh2Q5t5Lnj05wPQjZRjSZWKpJQzVzv/nN3BNwyholyAmOhymJnmqcm2fC6B\n\tnEk+TV70HAt2TaEiR8rN7w1QZmRi7g2hCS/oAwxFEQNwDR9bYSuLsoVc2hrrzlZnpE9c\n\tcK3VCe3pPlpp/lZYWbQbTRFidu2O1w6r0rOvtOe4S2LgIa8u5li/mzFD93T3pvwkWJT4\n\tp8rtxqVWQWa2aNrNqTWF22xlyHs/toQ/MnYK/xriOqeFNrRGM5DE3fD3lQQ9DGToIN+j\n\t2R/rhwlt+ntm2yJbywZyWDXrp3TFGWHQRlsYwvy1F25AVuRWuf8soP0WXlZiagT5MFf2\n\tta6A==","X-Gm-Message-State":"AHPjjUiV1hFW/4Ocm5WA29F99iEKxmkA6skXPYkWLYp+0pue0F3z1EPq\n\tcfLcYUlekRYj/Vn58QbPPPWfOg==","X-Google-Smtp-Source":"AOwi7QAJk5Bo4zWd2CHUqKjnBYPRqBa5Z4iBuD8lM4KeKFdBhs30GZwAJiR97e1FHZVhOcaKM6fsww==","X-Received":"by 10.223.135.141 with SMTP id b13mr1760609wrb.6.1505833698610; \n\tTue, 19 Sep 2017 08:08:18 -0700 (PDT)","References":"<20170919072719.11815-1-famz@redhat.com>\n\t<20170919072719.11815-5-famz@redhat.com>","User-agent":"mu4e 0.9.19; emacs 25.3.50.1","From":"Alex =?utf-8?q?Benn=C3=A9e?= <alex.bennee@linaro.org>","To":"Fam Zheng <famz@redhat.com>","In-reply-to":"<20170919072719.11815-5-famz@redhat.com>","Date":"Tue, 19 Sep 2017 16:08:17 +0100","Message-ID":"<8760ceenfi.fsf@linaro.org>","MIME-Version":"1.0","Content-Type":"text/plain; charset=utf-8","Content-Transfer-Encoding":"8bit","X-detected-operating-system":"by eggs.gnu.org: Genre and OS details not\n\trecognized.","X-Received-From":"2a00:1450:400c:c0c::22d","Subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.21","Precedence":"list","List-Id":"<qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<http://lists.nongnu.org/archive/html/qemu-devel/>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Cc":"Peter Maydell <peter.maydell@linaro.org>, qemu-devel@nongnu.org, Philippe\n\t=?utf-8?q?Mathieu-Daud=C3=A9?= <f4bug@amsat.org>,\n\tKamil Rytarowski <kamil@netbsd.org>, stefanha@redhat.com, \n\tCleber Rosa <crosa@redhat.com>, pbonzini@redhat.com","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"\"Qemu-devel\"\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>"}},{"id":1771163,"web_url":"http://patchwork.ozlabs.org/comment/1771163/","msgid":"<dbb8a1c1-a2a8-fb7d-1fea-f66da7417a89@redhat.com>","list_archive_url":null,"date":"2017-09-19T15:18:17","subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","submitter":{"id":6591,"url":"http://patchwork.ozlabs.org/api/people/6591/","name":"Eric Blake","email":"eblake@redhat.com"},"content":"On 09/19/2017 02:27 AM, Fam Zheng wrote:\n> This will be used by setup test user ssh.\n> \n> Signed-off-by: Fam Zheng <famz@redhat.com>\n> ---\n>  tests/keys/README     |  6 ++++++\n>  tests/keys/id_rsa     | 27 +++++++++++++++++++++++++++\n>  tests/keys/id_rsa.pub |  1 +\n>  3 files changed, 34 insertions(+)\n>  create mode 100644 tests/keys/README\n>  create mode 100644 tests/keys/id_rsa\n>  create mode 100644 tests/keys/id_rsa.pub\n> \n> diff --git a/tests/keys/README b/tests/keys/README\n> new file mode 100644\n> index 0000000000..f381ac0698\n> --- /dev/null\n> +++ b/tests/keys/README\n> @@ -0,0 +1,6 @@\n> +This folder contains a well-known key pair used in QEMU tests.\n\ns/key/ssh key/ ?\n\n> +\n> +Some guests require the key to exist prior to provisioning the guest; also,\n> +reusing a pre-built key avoids consuming entropy every time the testsuite is\n> +run.  Because the private key is well-known, care must be taken to use the key\n> +ONLY in situations that cannot be compromised by external network clients.\n\nThanks; that helps.\n\n> +++ b/tests/keys/id_rsa.pub\n> @@ -0,0 +1 @@\n> +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCikC46WYtXotUd0UGPz9547Aj0KqC4gk+nt4BBJm86IHgCD9FygSGX9EFutXlhz9KZIPg9Okk7+IzXRHCWI2MNvhrcjyrezKREm71z08j9iwfxY3340fY2Mo+0khwpO7bzsgzkljHIHqcOg7MgttPInVMNH/EfqpgR8EDKJuWCB2Ny+EBFN/3dAiff0X/EvKle9PUrY70EkSycnyURS8HZReEqj8lN9J5kXzA8F6jBo/0Q42Ttv6e4k5YcaDrwmLrBWLra2PCXZLNyHqXEiFkGmdXtA1Eox9gc/p4jIXim6xrPNmpN6WyrrEjaCF5xYvNv8wXkD6uSWwbHYU24lIAn qemu-test\n\nLet's make the comment even longer (I think you can use 'ssh-keygen -C\n\"some useful comment\"', but\nhttps://serverfault.com/questions/442933/add-comment-to-existing-ssh-public-key\nhas more information): maybe along the lines of:\n\nssh-rsa AAAAB...IAn well-known key for qemu-test, do not use on any\nmachine exposed to an external network\n\nBut either way,\n\nReviewed-by: Eric Blake <eblake@redhat.com>","headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=nongnu.org\n\t(client-ip=2001:4830:134:3::11; helo=lists.gnu.org;\n\tenvelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n\treceiver=<UNKNOWN>)","ext-mx02.extmail.prod.ext.phx2.redhat.com;\n\tdmarc=none (p=none dis=none) header.from=redhat.com","ext-mx02.extmail.prod.ext.phx2.redhat.com;\n\tspf=fail smtp.mailfrom=eblake@redhat.com"],"Received":["from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11])\n\t(using TLSv1 with cipher AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xxRxJ2WjTz9sMN\n\tfor <incoming@patchwork.ozlabs.org>;\n\tWed, 20 Sep 2017 01:43:48 +1000 (AEST)","from localhost ([::1]:43647 helo=lists.gnu.org)\n\tby lists.gnu.org with esmtp (Exim 4.71) (envelope-from\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>)\n\tid 1duKgc-00018N-GP\n\tfor incoming@patchwork.ozlabs.org; Tue, 19 Sep 2017 11:43:46 -0400","from eggs.gnu.org ([2001:4830:134:3::10]:60485)\n\tby lists.gnu.org with esmtp (Exim 4.71)\n\t(envelope-from <eblake@redhat.com>) id 1duKI9-0004bq-6c\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:18:31 -0400","from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71)\n\t(envelope-from <eblake@redhat.com>) id 1duKI6-0007Mq-Et\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:18:29 -0400","from mx1.redhat.com ([209.132.183.28]:58886)\n\tby eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)\n\t(Exim 4.71) (envelope-from <eblake@redhat.com>) id 1duKI6-0007Lg-5u\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 11:18:26 -0400","from smtp.corp.redhat.com\n\t(int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11])\n\t(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby mx1.redhat.com (Postfix) with ESMTPS id 26208806A6;\n\tTue, 19 Sep 2017 15:18:25 +0000 (UTC)","from [10.10.124.97] (ovpn-124-97.rdu2.redhat.com [10.10.124.97])\n\tby smtp.corp.redhat.com (Postfix) with ESMTP id 13B0E60466;\n\tTue, 19 Sep 2017 15:18:17 +0000 (UTC)"],"DMARC-Filter":"OpenDMARC Filter v1.3.2 mx1.redhat.com 26208806A6","To":"Fam Zheng <famz@redhat.com>, qemu-devel@nongnu.org","References":"<20170919072719.11815-1-famz@redhat.com>\n\t<20170919072719.11815-5-famz@redhat.com>","From":"Eric Blake <eblake@redhat.com>","Openpgp":"url=http://people.redhat.com/eblake/eblake.gpg","Organization":"Red Hat, Inc.","Message-ID":"<dbb8a1c1-a2a8-fb7d-1fea-f66da7417a89@redhat.com>","Date":"Tue, 19 Sep 2017 10:18:17 -0500","User-Agent":"Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101\n\tThunderbird/52.3.0","MIME-Version":"1.0","In-Reply-To":"<20170919072719.11815-5-famz@redhat.com>","Content-Type":"multipart/signed; micalg=pgp-sha256;\n\tprotocol=\"application/pgp-signature\";\n\tboundary=\"L6a6Tk3vp3Ofp6uNNOEwfECUVqsWRIvqF\"","X-Scanned-By":"MIMEDefang 2.79 on 10.5.11.11","X-Greylist":"Sender IP whitelisted, not delayed by milter-greylist-4.5.16\n\t(mx1.redhat.com [10.5.110.26]);\n\tTue, 19 Sep 2017 15:18:25 +0000 (UTC)","X-detected-operating-system":"by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic]\n\t[fuzzy]","X-Received-From":"209.132.183.28","X-Content-Filtered-By":"Mailman/MimeDel 2.1.21","Subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.21","Precedence":"list","List-Id":"<qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<http://lists.nongnu.org/archive/html/qemu-devel/>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Cc":"Peter Maydell <peter.maydell@linaro.org>, =?utf-8?q?Philippe_Mathieu-D?=\n\t=?utf-8?b?YXVkw6k=?= <f4bug@amsat.org>,\n\tKamil Rytarowski <kamil@netbsd.org>, stefanha@redhat.com, \n\tCleber Rosa <crosa@redhat.com>, pbonzini@redhat.com,\n\t=?utf-8?q?Alex_Benn=C3=A9e?= <alex.bennee@linaro.org>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"\"Qemu-devel\"\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>"}},{"id":1771526,"web_url":"http://patchwork.ozlabs.org/comment/1771526/","msgid":"<20170920031139.GE18491@lemon>","list_archive_url":null,"date":"2017-09-20T03:11:39","subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","submitter":{"id":24872,"url":"http://patchwork.ozlabs.org/api/people/24872/","name":"Fam Zheng","email":"famz@redhat.com"},"content":"On Tue, 09/19 10:18, Eric Blake wrote:\n> On 09/19/2017 02:27 AM, Fam Zheng wrote:\n> > This will be used by setup test user ssh.\n> > \n> > Signed-off-by: Fam Zheng <famz@redhat.com>\n> > ---\n> >  tests/keys/README     |  6 ++++++\n> >  tests/keys/id_rsa     | 27 +++++++++++++++++++++++++++\n> >  tests/keys/id_rsa.pub |  1 +\n> >  3 files changed, 34 insertions(+)\n> >  create mode 100644 tests/keys/README\n> >  create mode 100644 tests/keys/id_rsa\n> >  create mode 100644 tests/keys/id_rsa.pub\n> > \n> > diff --git a/tests/keys/README b/tests/keys/README\n> > new file mode 100644\n> > index 0000000000..f381ac0698\n> > --- /dev/null\n> > +++ b/tests/keys/README\n> > @@ -0,0 +1,6 @@\n> > +This folder contains a well-known key pair used in QEMU tests.\n> \n> s/key/ssh key/ ?\n\nYup.\n\n> \n> > +\n> > +Some guests require the key to exist prior to provisioning the guest; also,\n> > +reusing a pre-built key avoids consuming entropy every time the testsuite is\n> > +run.  Because the private key is well-known, care must be taken to use the key\n> > +ONLY in situations that cannot be compromised by external network clients.\n> \n> Thanks; that helps.\n> \n> > +++ b/tests/keys/id_rsa.pub\n> > @@ -0,0 +1 @@\n> > +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCikC46WYtXotUd0UGPz9547Aj0KqC4gk+nt4BBJm86IHgCD9FygSGX9EFutXlhz9KZIPg9Okk7+IzXRHCWI2MNvhrcjyrezKREm71z08j9iwfxY3340fY2Mo+0khwpO7bzsgzkljHIHqcOg7MgttPInVMNH/EfqpgR8EDKJuWCB2Ny+EBFN/3dAiff0X/EvKle9PUrY70EkSycnyURS8HZReEqj8lN9J5kXzA8F6jBo/0Q42Ttv6e4k5YcaDrwmLrBWLra2PCXZLNyHqXEiFkGmdXtA1Eox9gc/p4jIXim6xrPNmpN6WyrrEjaCF5xYvNv8wXkD6uSWwbHYU24lIAn qemu-test\n> \n> Let's make the comment even longer (I think you can use 'ssh-keygen -C\n> \"some useful comment\"', but\n> https://serverfault.com/questions/442933/add-comment-to-existing-ssh-public-key\n> has more information): maybe along the lines of:\n> \n> ssh-rsa AAAAB...IAn well-known key for qemu-test, do not use on any\n> machine exposed to an external network\n\nOK.","headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@bilbo.ozlabs.org","Authentication-Results":["ozlabs.org;\n\tspf=pass (mailfrom) smtp.mailfrom=nongnu.org\n\t(client-ip=2001:4830:134:3::11; helo=lists.gnu.org;\n\tenvelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n\treceiver=<UNKNOWN>)","ext-mx01.extmail.prod.ext.phx2.redhat.com;\n\tdmarc=none (p=none dis=none) header.from=redhat.com","ext-mx01.extmail.prod.ext.phx2.redhat.com;\n\tspf=fail smtp.mailfrom=famz@redhat.com"],"Received":["from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11])\n\t(using TLSv1 with cipher AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby ozlabs.org (Postfix) with ESMTPS id 3xxlCg1tdKz9s82\n\tfor <incoming@patchwork.ozlabs.org>;\n\tWed, 20 Sep 2017 13:12:12 +1000 (AEST)","from localhost ([::1]:46414 helo=lists.gnu.org)\n\tby lists.gnu.org with esmtp (Exim 4.71) (envelope-from\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>)\n\tid 1duVQm-0005Ot-HC\n\tfor incoming@patchwork.ozlabs.org; Tue, 19 Sep 2017 23:12:08 -0400","from eggs.gnu.org ([2001:4830:134:3::10]:36569)\n\tby lists.gnu.org with esmtp (Exim 4.71)\n\t(envelope-from <famz@redhat.com>) id 1duVQT-0005OL-Fv\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 23:11:50 -0400","from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71)\n\t(envelope-from <famz@redhat.com>) id 1duVQQ-0000Zt-BO\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 23:11:49 -0400","from mx1.redhat.com ([209.132.183.28]:41674)\n\tby eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)\n\t(Exim 4.71) (envelope-from <famz@redhat.com>) id 1duVQQ-0000Xd-4V\n\tfor qemu-devel@nongnu.org; Tue, 19 Sep 2017 23:11:46 -0400","from smtp.corp.redhat.com\n\t(int-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.12])\n\t(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby mx1.redhat.com (Postfix) with ESMTPS id 178F281DF1;\n\tWed, 20 Sep 2017 03:11:45 +0000 (UTC)","from localhost (ovpn-12-90.pek2.redhat.com [10.72.12.90])\n\tby smtp.corp.redhat.com (Postfix) with ESMTP id 745F260BE2;\n\tWed, 20 Sep 2017 03:11:41 +0000 (UTC)"],"DMARC-Filter":"OpenDMARC Filter v1.3.2 mx1.redhat.com 178F281DF1","Date":"Wed, 20 Sep 2017 11:11:39 +0800","From":"Fam Zheng <famz@redhat.com>","To":"Eric Blake <eblake@redhat.com>","Message-ID":"<20170920031139.GE18491@lemon>","References":"<20170919072719.11815-1-famz@redhat.com>\n\t<20170919072719.11815-5-famz@redhat.com>\n\t<dbb8a1c1-a2a8-fb7d-1fea-f66da7417a89@redhat.com>","MIME-Version":"1.0","Content-Type":"text/plain; charset=us-ascii","Content-Disposition":"inline","In-Reply-To":"<dbb8a1c1-a2a8-fb7d-1fea-f66da7417a89@redhat.com>","User-Agent":"Mutt/1.8.3 (2017-05-23)","X-Scanned-By":"MIMEDefang 2.79 on 10.5.11.12","X-Greylist":"Sender IP whitelisted, not delayed by milter-greylist-4.5.16\n\t(mx1.redhat.com [10.5.110.25]);\n\tWed, 20 Sep 2017 03:11:45 +0000 (UTC)","X-detected-operating-system":"by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic]\n\t[fuzzy]","X-Received-From":"209.132.183.28","Subject":"Re: [Qemu-devel] [PATCH v9 04/13] tests: Add a test key pair","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.21","Precedence":"list","List-Id":"<qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<http://lists.nongnu.org/archive/html/qemu-devel/>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n\t<mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Cc":"Peter Maydell <peter.maydell@linaro.org>, qemu-devel@nongnu.org, Philippe\n\t=?iso-8859-1?q?Mathieu-Daud=E9?= <f4bug@amsat.org>,\n\tKamil Rytarowski <kamil@netbsd.org>, stefanha@redhat.com, \n\tCleber Rosa <crosa@redhat.com>, pbonzini@redhat.com, Alex\n\t=?iso-8859-1?q?Benn=E9e?= <alex.bennee@linaro.org>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"\"Qemu-devel\"\n\t<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>"}}]