3 ms·
Because your users cannot be trusted. I run servers which coworkers, all developers, get access to. It's either ssh keys or 2 factor authentication because most
by tokenizerrr 9y ago
Because your users cannot be trusted. I run servers which coworkers, all developers, get access to. It's either ssh keys or 2 factor authentication because most don't give a fuck about security and will insist using garbage passwords if not prevented from doing so (and then they will complain), even though the use of a password manager is mandatory.
- logicallee 9y agoPerfect answer actually. Accepted and I've updated my original comment.
- jlgaddis 9y ago> ... will insist using garbage passwords if not prevented from doing so ... /etc/security/pwquality.conf is how I prevent co-workers from doing so (on RHEL and derivatives).
- tokenizerrr 9y agoGood to know. We do our user provisioning through an internal portal which enforces everything. The ssh servers als gets configured to disable password login so the only thing passwords are used for is sudo. All web stuff is behind a SSO gateway with password+2fa.