Re: How to configure dual SSH keys?



mb <michaelb@xxxxxxxxxxx> wrote:
Darren Dunham wrote:
<snip>
...A particular running OpenSSH is only going to have
one set of host keys. You could connect to another server (perhaps
running on another port) to access the alternate keys.

Use HostKey with the alternate server to point to the alternate
location.

Then you can deny root access on the normal server and allow it on this
one.

That sounds workable. Is there any reason why root access couldn't be
allow for all clients, and the one special client would just connect
explicitly to the second sshd's port?

Root access isn't a facility of the client, its a facility of the
server. There's nothing special about the client (although you might be
supplying some different arguments to it for connection information).

So, yes you can allow root access on both servers, but that might not be
getting you any extra security. (Of course you might not be looking for
that).

--
Darren Dunham ddunham@xxxxxxxx
Senior Technical Consultant TAOS http://www.taos.com/
Got some Dr Pepper? San Francisco, CA bay area
< This line left intentionally blank to confuse you. >
.



Relevant Pages

  • Re: Unable to print to networked printer - get access denied messa
    ... Check the permissions on the server assuming the client has a true RPC ... How is the Standard TCP/IP port configured for the device? ...
    (microsoft.public.windowsxp.print_fax)
  • Re: interfaces lo:1 lo:2 lo:3? (for remote ssh tunnels)
    ... That's the problem tunneling (port forwarding) solves. ... >>can't get past the client firewall. ... > I don't understand why the server would be making the ... server initiates another connection to the client -- in this ...
    (Debian-User)
  • Re: Remote Connection Issue
    ... through port number 3389 and a workstation on the LAN through port number ... I understand that you want to allow a LAN client ... and you have configured server publishing rule ... > By default Terminal Server and Windows 2000 Terminal Services uses TCP ...
    (microsoft.public.windows.server.sbs)
  • Re: RealVNC
    ... Default listening port for RealVNC server that runs on the machine on which ... Then there is default Java listening port on port 5800 on the client machine ...
    (microsoft.public.windows.server.sbs)
  • Re: Redirecting data sent to a local printer to another host and port on the network
    ... All client workstations have access to the ... simply redirecting netcat traffic on port 9100 to port 515 on ... Only LPR clients talk to LPD print server daemons. ... >workstation at the branch site where the print job originated. ...
    (comp.unix.sco.misc)