Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SSH Authentication



At 10:03 AM -0400 8/30/05, Edward Marczak wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On Aug 29, 2005, at 9:18 PM, Dan Shoop wrote:

You can restrict it based on IP *and* user.

Yes, in other ways you can. But not with "PermitRootLogin", which is what I was responding to.

Yes but it was /my/ point, that you have much finer access control in configuring sshd than compared to blocking IPs at firewalls, in xinetd , et al.


That is that there's much finer granularity than just turning off root for ssh, which is only a partial solution.

If you're concerned about the snipes against root, why wouldn't you be concerned about the snipes against "admin", and other popularly attacked accounts. Likewise if you wish to secure root for due diligence, not permitting direct ssh into privileged accounts, then you're also missing the mark by half by not also securing any other privileged accounts, such as those with admin status.
--


-dhan

------------------------------------------------------------------------
Dan Shoop                                                   AIM: iWiring
Systems & Networks Architect                     http://www.iwiring.net/
email@hidden                                 http://www.ustsvs.com/

pgp key fingerprint: FAC0 9434 B5A5 24A8 D0AF  12B1 7840 3BE7 3736 DE0B

iWiring provides systems and networks support for Mac OS X, unix, and
Open Source application technologies at affordable rates.
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Re: SSH Authentication (From: "Jose L. Hales-Garcia" <email@hidden>)
 >Re: SSH Authentication (From: Edward Marczak <email@hidden>)
 >Re: SSH Authentication (From: Dan Shoop <email@hidden>)
 >Re: SSH Authentication (From: Edward Marczak <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.