Add new comment
Do you like HowtoForge? Please consider supporting us by becoming a subscriber.
|
SSH is a great, secure tool and these suggestions are great. I would add that if you need to be PCI compliant or face some other audit requirements, you might need something more than public-key authentication. With SSH public-key authentication:
There is no way to control which users have public key authorization There is no way to enforce passphrase complexity (or even be sure that one is being used) There is no way to expire a public key as I discussed here:http://www.howtoforge.com/secure_ssh_with_wikid_two_factor_authentication nick
Reply |





Recent comments
10 hours 28 min ago
16 hours 16 min ago
18 hours 8 min ago
19 hours 53 min ago
23 hours 43 min ago
1 day 5 hours ago
1 day 5 hours ago
1 day 9 hours ago
1 day 15 hours ago
1 day 20 hours ago