RE: remote ssh for root

From: Don Gray (don_gray_at_busdk12.com)
Date: 05/06/05

  • Next message: Mojito Jones: "RE: Login Attempt Limits"
    Date: Fri, 6 May 2005 14:51:25 -0700
    To: <secureshell@securityfocus.com>
    
    

    Not sure about AIX but it should be similar, this is what I don on my Linux
    and UNIX systems:

    Connect with another user that is in the wheel group then use su to elevate
    to root.

    -----Original Message-----
    From: daniel.engelsen@caremark.com [mailto:daniel.engelsen@caremark.com]
    Sent: Friday, May 06, 2005 9:22 AM
    To: secureshell@securityfocus.com
    Subject: remote ssh for root

    I would like to setup a trusted host that utilizes ssh; however, I do not
    want root to be loginable. If I set PermitRootLogin to no, then the remote
    ssh function stops as well. Does anyone know of a way to be able to do
    remote ssh's as root without allowing root to be able to login?

    I am using AIX versions 5.1, 5.2, and 5.3, and we are running ssh versions
    3.6 and 3.8.

    Any ideas would be greatly appreciated.

    Thanks,


  • Next message: Mojito Jones: "RE: Login Attempt Limits"

    Relevant Pages

    • Re: PermitRootLogin=yes versus su
      ... > a regular user and using su to become root. ... > Back in the days before strong encryption, when remote access was done ... > However, we now have SSH. ...
      (comp.security.ssh)
    • Reasoning behind a default remote root login ?
      ... using ssh. ... remote root logins alltogether. ... Does anyone know why OpenBSD allows remote root ...
      (comp.unix.bsd.openbsd.misc)
    • PermitRootLogin=yes versus su
      ... a regular user and using su to become root. ... Back in the days before strong encryption, when remote access was done ... However, we now have SSH. ... Logging in as a regular user via SSH, then using su to become root, ...
      (comp.security.ssh)
    • Re: Restricting access to a web server by IP
      ... > remote control clients, etc - we remotely ... > The agrument against is that mpst vulnerabilities seem to come through ... > servers, and blocking access to all IPs accept those on the allowed list - ...
      (comp.security.misc)
    • Re: Restricting access to a web server by IP
      ... > remote control clients, etc - we remotely ... > The agrument against is that mpst vulnerabilities seem to come through ... > servers, and blocking access to all IPs accept those on the allowed list - ...
      (comp.security.firewalls)