3 ms·
> * enforcing SSH key authentication That cannot be enforced by the server because the key decryption occurs client-side. An alternative is to use Two Factor A
by sdeziel 9y ago
> * enforcing SSH key authentication
That cannot be enforced by the server because the key decryption occurs client-side. An alternative is to use Two Factor Authentication.
- e12e 9y agoI think you mean the server can't enforce ssh key encryption/passphrase protection (next point down)? And 2 or even 3 factor should maybe be on the list (key+pw, key+totp, key+pw+totp). For keys, it's in theory possible to ease management with using ssh certificates and a CA - anyone know of a convenient way to manage totp secrets across multiple servers and users?
- sdeziel 9y agoYeah, I quoted the wrong line.
- deleted 9y ago[deleted]