Generate the public/private pair on the client machine and the public key is the one you put on other machines to SSH into them.
Generate the public/private pair on the client machine and the public key is the one you put on other machines to SSH into them.
And if you do require both directions, you should generate separate keys on each host and just exchange the public ones.
Unfortunately for network security, that seems less and less the case these days. I definitely find myself ssh'd into two remote systems relatively often and have a need to copy files between the two. (Swapping arguments to scp is not good enough.)
An example would be a cron job that copies files to a backup server via scp or rsync over ssh. However, this should also be accompanied by host filters in the authorized_keys file to restrict access to specific hosts.
Using pastebin for this is wrong on so many levels.
I can't think of any reason at all to copy the private key though.
Sysadmin has two worksations - say a laptop and a desktop. He wants to SSH into all his remote boxen from either. The default reaction might be to just copy his already-authorized private key to his other machine just for ease of use - the proper solution would be to generate a new keypair on the new machine and then copy it to the required remote machines as well, so either can be revoked and tracked separately.
for example, copy file from local machine:
scp some_file.tar.gz alex@remote_ip:~/
now copy the same file from a remote to the local machine:
scp alex@remote_ip:~/some_file.tar.gz ~/
But seamless logins form anywhere to anywhere in the way you described seems like a bad idea, unless you are willing to implement kerberos, ldap and nfs4, in this way you can just log in into a client machine using your existing credentials (see PAM) and if you have your home directory property mounted you can have public/private keypair on that machine. But this is a lot of work.
Why does everyone seem to think it's okay to build a system where any one compromised box can compromise the rest of the system? this 'jelly doughnut security' is really popular among the PHB types, because it's easy, but it just seems really, really dangerous.