4 ms·
The title of this doesn't properly match the contents. This is basically a how to set up an enterprise SSH environment using certificates. This doesn't tell you
by jonluca 7y ago
The title of this doesn't properly match the contents. This is basically a how to set up an enterprise SSH environment using certificates. This doesn't tell you anything about "How to SSH Properly".
- Aachen 7y agoI almost thought so too and was itching to hit back and post an annoyed comment, but there are actually two more sections: using 2FA (straightforward TOTP branded by our favorite not-evil corp though I've not no idea what they've got to do with it) and setting up a jump host / bastion host. So maybe the title shouldn't be "I like ssh certs" but "ssh security for organisations", but your point still stands.
- mynameisvlad 7y ago> though I've not no idea what they've got to do with it) It's the name of the TOTP PAM module they use, which was created by Google: https://github.com/google/google-authenticator-libpam https://github.com/google/google-authenticator-libpam
- webvictim 7y agoAuthor here - thanks for the feedback. As another reply points out, I did try to also cover the use of a bastion host along with one form of 2-factor authentication. I'm considering doing a future post on how to set up U2F for SSH with hardware devices (like a Yubikey) as well. I'm curious if you have anything else you'd like to see on this topic.
- jlgaddis 7y agoThe company that authored this "How to SSH Properly" blog post sells a product that will enable you to use SSH "properly" (according to their definition). That's not a coincidence, of course. It's purely sales and marketing. To be clear, the ultimate goal of this blog post is simply to get you or your employer to give them some of your money -- that's it. (To be clear, giving an external entity full control over authentication and authorization of your critical servers is definitely not doing "SSH properly", IMO!)