Mailing Lists: Apple Mailing Lists
Image of Mac OS face in stamp
Re: SSH Authentication
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SSH Authentication



Title: Re: SSH Authentication
At 5:35 AM -0700 8/29/05, Jose L. Hales-Garcia wrote:
On Jul 17, 2005, at 7:44 PM, Chad Morris wrote:

I need my users to be able to connect to my OD Master via SSH.  The users are in the LDAP directory.  Is this possible?

I would just add that you should secure your server against SSH brute force probes.  There is a great deal of it going on.  On server product root has a shell and by default SSH is configured to allow remote root access.  I highly recommend turning this behavior off.  It can be done using the firewall or with other products like snort.  But the quick way is to set PermitRootLogin to no in file /etc/sshd_config.

It's actually much better, and more appropriate, to restrict users/IP-addresses for ssh, *in* ssh, since this give level 7 granularity.
--

-dhan

------------------------------------------------------------------------
Dan Shoop                                                   AIM: iWiring
Systems & Networks Architect                     http://www.iwiring.net/
email@hidden                                 http://www.ustsvs.com/

pgp key fingerprint: FAC0 9434 B5A5 24A8 D0AF  12B1 7840 3BE7 3736 DE0B

iWiring provides systems and networks support for Mac OS X, unix, and
Open Source application technologies at affordable rates.
 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

References: 
 >Re: SSH Authentication (From: "Jose L. Hales-Garcia" <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2011 Apple Inc. All rights reserved.