Re: How to secure SSH from low security app server to high security DB server?



Snewber wrote:
We need to be able to run commands from a low security application server (as this is running web servers and thus a large number of people have access to the web servers) to a high security database server. I would like to use SSH (maybe a locked down ssh server) to do this but the system administrators will not allow this as they say that if a bug is found with the SSH server then the secure database server could be compromised by the compromised SSH server. The sysadmins want us to come up with another way of running commands on the database server from the application server.

I think that doing it another way is like reinventing the wheel, why use another method when SSH was probably designed to do this? Or, is there a better way of doing this?


LOW SECURITY APPLICATION SERVER

----------FIREWALL-------------

HIGH SECURITY DATABASE SERVER

have the admin setup protocol 2 pass=phrase authentication and deny all other forms. (s)he should be VERY pleased with that level of login as it requires your public key file to be located on the target ssh server.



-- --- Jeff B (remove the No-Spam to reply) .



Relevant Pages

  • How to secure SSH from low security app server to high security DB server?
    ... We need to be able to run commands from a low security application server to a high security database server. ... I would like to use SSH (maybe a locked down ssh server) to do this but the system administrators will not allow this as they say that if a bug is found with the SSH server then the secure database server could be compromised by the compromised SSH server. ...
    (comp.security.ssh)
  • Re: Openssh-server installation in etch
    ... Every distribution I used such as Fedora, SUSE, ... and even sarge installed ssh server ... apt-cache search server yields a bit more, actually far too much to list ... scanssh - get SSH server versions for an entire network ...
    (Debian-User)
  • RE: ISA 2004 Connectivity to Internal Web Servers
    ... Open ISA Server 2004 Admin Console ... Bypass proxy for Web servers in this network ... Sill in Web Browser tab, click Add button to open Add Server window. ... when all internal clients attempt to ...
    (microsoft.public.isa)
  • Re: SSL Publishing issue (error 500 Target principal name is incorrect - 2146893022)
    ... servers I have assigned a cert with their internal FQDN and changed the ISA ... > The ISA server uses internal DNS servers to name resolution. ... > exported as PFX and imported onto both web servers and the ISA server. ...
    (microsoft.public.isa.publishing)
  • Re: Securing web site with redundancy ?
    ... Load balancing inserts complexity though. ... Securing web site with redundancy? ... If one server goes down the DNS ... My web servers are web servers only, not at all DNS servers ... ...
    (Security-Basics)