Skip to main content

py-vmsshgen

Automatic generation of SSH keys for VM.

Why?

I got tired of provisioning SSH keys manually between hundreds of VMs that I had to use.

How to use?

The script generates OpenSSH keypair and pushes public key to VM using existing SSH connection that can be protected by password (or some another SSH key). The private key on client machine (that executes this application) automatically goes to ~/.ssh/{name}.pem + reference to it is appended to ~/.ssh/config for automatic pickup by SSH client configuration.

Supported parameters for key generation - https://asyncssh.readthedocs.io/en/latest/api.html#asyncssh.generate_private_key
Supported parameters for private key export - https://asyncssh.readthedocs.io/en/latest/api.html#asyncssh.SSHKey.export_private_key

Default settings:

  • Algo for generation - ssh-ed25519
  • No passphrase
  • Output private key with cipher AES256 with SHA256 hashing and 128 rounds of bcrypt.

You can install it using pip
pip install vmsshgen

All actions are done interactively in terminal:

usage: vmsshgen [-h] [-n N] [-a ALGO] [-ks KEY_SIZE] [-e EXPONENT] [-p PASSPHRASE] [-c CIPHER] [-r ROUNDS] [-hn HASH_NAME] host {password,privatekey} username pf

positional arguments:
  host                  VM hostname:port (example localhost:22)
  {password,privatekey}
                        login type
  username              VM username
  pf                    Password file location

optional arguments:
  -h, --help            show this help message and exit
  -n N, --name N        name for public/private key
  -a ALGO, --algorithm ALGO
                        algorithm for keypair (default is ssh-ed25519)
  -ks KEY_SIZE, --key-size KEY_SIZE
                        key size (only for RSA)
  -e EXPONENT, --exponent EXPONENT
                        exponent (only for RSA)
  -p PASSPHRASE, --passphrase PASSPHRASE
                        passphrase for OpenSSH key (default is None)
  -c CIPHER, --cipher CIPHER
                        cipher for OpenSSH key (default is aes256)
  -r ROUNDS, --rounds ROUNDS
                        rounds for OpenSSH key (default is 128)
  -hn HASH_NAME, --hash-name HASH_NAME
                        hash name for OpenSSH key (default is sha256)

Example with password file on linuxserver.io with password password stored in file named pf:
vmsshgen -n test localhost:2222 password linuxserver.io pf

Of course, if you want to supply password right inside of same commandline statement, there's an option using FIFO pipe:
vmsshgen -n test localhost:2222 password linuxserver.io <(echo 'password')

(Honestly, if you decided to go with this option, I suggest to ensure that history for current shell is disabled or you enter space in front of command to avoid leaking password in history)

Metadata

Release files for vmsshgen 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vmsshgen 1.0.2
File Size Uploaded
vmsshgen-1.0.2.tar.gz 8.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vmsshgen 1.0.2
File Interpreter ABI Platform
vmsshgen-1.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 18.2 kB

Release files / vmsshgen-1.0.2.tar.gz

Download URL vmsshgen-1.0.2.tar.gz
Size 8.7 kB
Tags Source
SHA-256 checksum
How to use checksums
a8d3126ba695811d17835462721059a9e323fe09fd20ad31131e41376b051657
BLAKE2b-256 checksum
How to use checksums
2c178b1ab1d520d011a9e8ed34081bbc232945cff9043e99391538bdc5516bf1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.13

Release files / vmsshgen-1.0.2-py3-none-any.whl

Download URL vmsshgen-1.0.2-py3-none-any.whl
Size 9.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4d834afb2fad274dc2a03d015bd9394e1acfa461a99cbbe0a1889728897506b6
BLAKE2b-256 checksum
How to use checksums
79bc66169f7fe74ff023dce0b79e668d954850954e59748ccfcc04039ad1fb7e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.6.0 importlib_metadata/4.8.2 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.9.13

Release history Release notifications | RSS feed

This release

1.0.2 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page