Re: Multiple authorized_keys2 files or how to achieve same effect.

From: Johan De Meersman (jdm_at_operamail.com)
Date: 09/02/05

  • Next message: Johan De Meersman: "Re: User name prompt with ssh"
    Date: Fri, 02 Sep 2005 10:49:16 +0200
    To: Jeremy Eder <jeder@invision.net>
    
    
    

    Jeremy Eder wrote:

    >My situation: multiple admins needing root on hundreds of boxes.
    >
    >Currently: using pubkeyauth on openssh (mostly bsd but linux and
    >solaris too)
    >
    >Goal: ease add/remove of credentials from machines (one-off or globally
    >in our network)
    >
    >

    Why not use SSH with PAM authentication against a central backend such
    as a mysql database or an LDAP service ?

    -- 
    You will never know hunger.
    -- 
    Public GPG key at blackhole.pca.dfn.de
    GCS/IT d- s:+ a- C(+++)$ UL++++$ P+++(++++)$ L++(+++)$ !E- W+(+++)$
    N+(++) o K w$ !O !M V PS(++)@ PE-(++)@ Y+ PGP++(+++) t(+) 5 X R tv--
    b++(++++) DI++(++++) D++ G e++>+++++ h(+) r y+**
    
    



  • Next message: Johan De Meersman: "Re: User name prompt with ssh"

    Relevant Pages

    • Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?
      ... >> I start by not giving logins and SSH access to users I don't trust. ... a network topology which goes around the ... >> firewall and thus is a serious hole to network security. ... >> have access via UPnP to, well, anything that device might happen to ...
      (Firewall-Wizards)
    • Re: Security Breached
      ... I have a typical home network that looks like this: ... on both the DMZ and port forward questions. ... I have the vnc port blocked at the router so I presumed it was safe to ... they done it port forwarding over SSH (if your assumption of only SSH ...
      (alt.computer.security)
    • server securing issues
      ... have done some securing on my solaris server and ... Information about the remote host: ... Port ssh ... An SSH server is running on this port. ...
      (SunManagers)
    • Re: Questions on some wierd /var/log entries
      ... How do I find out if I'm on an ipv6 network? ... That is because I prefer using iptables directly. ... then you should start learning about its firewall ... Another important restriction for ssh is to authenticate by certificate ...
      (comp.os.linux.misc)
    • Re: use ipchains to block all ports > 60,000
      ... Now what version of ssh is ... Put the suggested hub between the box and the internet, ... >> By temporarily breaking the network connection and inserting a hub ... evidence of users you know not of appearing on ...
      (comp.os.linux.security)