Menu

Main Menu
Talk Get Daily Search

Member's Online

    User Name
    Password

    Problems using public key authentication in N900.

    Reply
    Page 3 of 3 | Prev |   1     2   3 |
    strank | # 21 | 2009-12-13, 10:22 | Report

    Originally Posted by cowb0y View Post
    I'm not sure of any reason to not give the user account a password (on this platform). ... I also recommend assigning a strong root password, to help insulate against generic userland exploits.

    If the passwordless method described is chosen, the user MUST disable password authentication in /etc/ssh/sshd_config (or anyone connecting will be granted shell access (and presumably, soon thereafter, root)).
    Amen to the strong root password! However, the method described does not allow passwordless logins, on the contrary, since "NP" is not the hash of any password, login with password is now impossible both locally (as before) and via ssh. (I just verified that by changing my sshd_config and trying.)

    My reasoning for not assigning 'user' a password is to avoid any conflicts with other changes during system updates. (Extra file instead of changed file, I still have a root password hash in /etc/passwd though...)
    It does not really make a big difference probably, it is, however, actually more secure than assigning a password!

    Nevertheless...

    Originally Posted by cowb0y View Post
    I recommend the following settings, regardless:

    PermitRootLogin no
    PasswordAuthentication no
    ... what cowb0y said.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 2 Users Say Thank You to strank For This Useful Post:
    qole, wumpwoast

     
    cowb0y | # 22 | 2009-12-13, 22:27 | Report

    Thanks for the clarification.

    Edit | Forward | Quote | Quick Reply | Thanks

     
    Page 3 of 3 | Prev |   1     2   3 |
vBulletin® Version 3.8.8
Normal Logout