I'm considering requiring users on my system to use keyed SSH to connect. We're already taking steps for SSH security by binding it to an off IP and port, but my paranoid mind says that's not enough.
Is it really all that much added security to require users who wish to use SSH to generate keys, importing the public key via cPanel?
My thinking is that - eventually - someone is going to get stupid, and use an insecure password, and jailshell or no, I don't want that to happen, should they get cracked.
The problem I'm thinking we'd run into is the user creating a pub/priv key pair, uploading the public, and then not password protecting the private. If they're on a non-shared system, then that's perfectly fine. If they're on a shared system, that's a huge security risk.
Suggestions?
Comments?
Thoughts?
-Eric Scalf
CMH Onsite Solutions
CMHZ Networks
Is it really all that much added security to require users who wish to use SSH to generate keys, importing the public key via cPanel?
My thinking is that - eventually - someone is going to get stupid, and use an insecure password, and jailshell or no, I don't want that to happen, should they get cracked.
The problem I'm thinking we'd run into is the user creating a pub/priv key pair, uploading the public, and then not password protecting the private. If they're on a non-shared system, then that's perfectly fine. If they're on a shared system, that's a huge security risk.
Suggestions?
Comments?
Thoughts?
-Eric Scalf
CMH Onsite Solutions
CMHZ Networks
Last edited: