basic shell access problem

From: Micha³ Kurowski (mkur_at_poczta.gazeta.pl)
Date: 10/08/05


Date: Sat, 8 Oct 2005 17:06:41 +0000 (UTC)

Hi,

I'd like to ask for your advice on basic shell access problem.

This is actually much more a policy problem then a technical ssh
question but I think it is pretty much very relevant for this group.

We want to allow selective shell access to our "gateway" server for
remote hosts. We already have contemporary "blacklisting" solution to
kick out usual account cracking trials.

We also employ "AllowUsers" sshd_config solution to permit specific
user/IP combinations. In practice it is becoming really annoying for
both maintainers and users though. It is very tempting for some people
to put a "user@*" entry in there ...

How do you people manage this ?

I know there are many possibilities. Allowing public keys based logins
only is not am option because we have to many undereducated users
(using unsafe computers). VPN-like solution is also an overkill for
us. I am leaning towards some solution placed in the router/firewall
rather then on a specific server.
 
Any comment highly appreciated.

-- 
Michal Kurowski
<mkur@poczta.gazeta.pl>


Relevant Pages

  • sFTP compared with FTP via VPN
    ... I am trying to setup a server to allow third party users to place ... SSH which seemed to be the solution. ... shell access is creating vulnerabilites that I am not aware of. ...
    (comp.security.unix)
  • Re: Pine Server installation Recommendation
    ... If you want shell access to a well-run mail server, ... At panix you pay other ... for shell access and 800MB total storage. ...
    (comp.mail.pine)
  • Re: Limiting User Commands
    ... Don't give them shell access, and don't let them ftp to the server. ... You could allow the apache user to ... To UNSUBSCRIBE, email to debian-isp-REQUEST@lists.debian.org with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: Deny local socket/port binding on server.
    ... Thanks Tim. ... plenty of reasons to limit this on a server. ... while they have shell access, they can't do certain things they ought ... solution to a problem, or to secure the system, but that it's just one ...
    (comp.os.linux.security)
  • Re: Deny local socket/port binding on server.
    ... Thanks Tim. ... plenty of reasons to limit this on a server. ... while they have shell access, they can't do certain things they ought ... solution to a problem, or to secure the system, but that it's just one ...
    (comp.security.unix)