8 ms·
SSH Emergency Access
- noodlesUK 6y agoI think another thing we might want to learn about is how to sound the alarm when the break glass is used. Is there an easy way of doing that with SSH? Running a command to page the ops/security team when a server receives a login attempt with an emergency credential?
- nix23 6y agoMaybe monitor the Emergency Machine itself? If it boot's up, emergency credentials are probably used? But really good point, and i love the analogy to 'break glass'
- withinboredom 6y agoYou can physically put the (yubikey) device in a vault that will physically sound an alarm when opened. It could also have a battery-powered arduino inside the box (with SIM breakout) that texted the devops team when opened.
- chrisweekly 6y agoNo idea why you were downvoted; it seems like a reasonable idea to me. (Also, IMHO downvoting a good-faith comment like yours is a lazy alternative to posting a substantive response.)
- BillinghamJ 6y agoOvercomplex technical solution to a simple problem. Besides which, if you really want to go full-on with technically clever solutions, keep in mind you could ensure no cellular service prior to opening. But then we're just getting into the realms of silly situations.
- dcow 6y agoWould you attempt to use the key if you knew the CTO, SRE and OPS teams were paged as soon as the safe was accessed?
- lormayna 6y agoYou can use pam-hooks module to execute scripts at login/logout.
- andylynch 6y agoThere are tools like Powerbroker which do this, and also privileged access management more generally - popular at banks and the like. Also SSH (the company)
- aidos 6y agoYou can add a script at ~/.ssh/rc that’s run on each login. You’d need to be careful to make sure it couldn’t be changed if you were relying on it for notifications.
- gnufx 6y agoHow do you record the key used from that (assuming that's what's required)?
- gnufx 6y agoI don't know what it looks like for a certificated system, but syslog records the private key used for login in a fairly vanilla Debian. If you worry about things like that and aren't looking at physical access (as suggested elsewhere), you presumably have remote syslog and audit which you can check.
- tashian 6y agoHey there, I wrote this post. It's a great question. One benefit of using certificates for emergency access is that SSHD logging can be configured to show a lot more detail about the certificate that was used. With public keys, there isn't anything to show. But with certificates you have a key ID, serial number, principals, CA fingerprint, etc. So, that log is a good hook for sounding the alarm. A more advanced version of this would allow you to record a reason for using the emergency access key when the connection is made (or when sudo is used).
- jlgaddis 6y ago> With public keys, there isn't anything to show. There's, at minimum, client IP address, username, and the key fingerprint -- which has always been good enough for me. There might be even more details available but I'm not sitting in front of a computer to check.
- rsync 6y ago"I think another thing we might want to learn about is how to sound the alarm when the break glass is used. Is there an easy way of doing that with SSH?" Yes - quite simple and old-fashioned, actually ... I have this line in the SSH users' .login file: /usr/local/sbin/sms 4153331111 4158882222 "USER LOGIN TO XXX - $DATE" >& /dev/null ... where the 'sms' command, above, is a shell script I wrote to call twilio messaging with the curl command. A very simple example of that would be: curl -X POST -d "Body=$msg" -d "From=$from" -d "To=$to" "https://api.twilio.com/2010-04-01/Accounts/$accountsid/Messages" -u "$accountsid:$authtoken" ... and this works like a charm. Alternatively, you could rick-roll your on-call sysadmin: /usr/local/bin/curl -XPOST https://api.twilio.com/2010-04-01/Accounts/$accountsid/Calls.json --data-urlencode "To=$number" --data-urlencode "From=$callerid" --data-urlencode "Url=http://demo.twilio.com/docs/voice.xml" -u $accountsid:$authtoken (the voice.xml demo is, in fact, Rick Astley)
- 8organicbits 6y agoLogin shell for emergency accounts could be a script that "sounds the alarm" and then drops to a bash shell. Edit: ooo @rsync just gave another good approach
- jlgaddis 6y agoGenerating alerts from syslog messages is something that we've been doing for decades.
- masonhensley 6y agoNeat - something I feel that often gets overlooked in most SAAS systems (think internal side) be it customer service, ops, etc tooling is break the glass escalation functionality. Most systems I’ve seen in the wild completely lack this and will result in over provisioning of admin “god mode” accounts. NoodlesUK points out alerting which is a pretty important concept to incorporate. Largely a solved concept in Electronic Medical Records & as outlined in the post.
- modinfo 6y agoWhat a coincidence, 3 days ago I ordered two pieces of yubikey 5, today arrived a package and today I read a post on how to use them in an interesting way for emergency access to my server via SSH. I'd like to add that the way it's described really works. But... Now I don't know to leave one yubikey in case I need to use it for emergency access to ssh? I have a server since 2011 and I have never problems with access through ssh, I use the same keys to this day and everything works. I think this way with yubikey to emergency access is overkill. It's just an interesting way to use yubikey.
- danmur 6y agoIf you need to the option to give someone temporary access it seems like a good option. I don't think it would add anything to my personal stuff since there's no reason I can think of to give someone else access. At work definitely.
- dcow 6y agoRight, this is more about a cryptographic grant of temporary emergency access to someone who doesn't have a user account or admin keys already on a machine (and ideally nobody should have persistent admin access in a well-oiled production setting) in the event that existing access control mechanisms have failed. And backing the signing operations by a YubiKey lets you physically secure the key in ways that you wouldn't an entire laptop and provides all the benefits of tamper resistant, proximity aware, hardware. Probably not something most people will want or need to bother with for personal stuff, but very reasonable expectation as soon as you're working on a team or managing many hosts, etc.
- ascotan 6y agoI don't get it. When would u need a backup ssh key other than if a user lost access? Most VMs have console access for this purpose.
- asdfasgasdgasdg 6y agoI'm not sure of the exact scenario but I would just note that there are other types of computing environments than virtual machines. For example, there a physical machines, sometimes hosted in a colo where you have no employees on the ground.
- gnufx 6y agoSurely you'd have some sort of remote KVM in such cases (like IPMI, as mentioned in another comment). That's critical in the clusters I've run and, of course, the manufacturers' implementation of that critical functionality in IPMI is likely to be rubbish and you can't get it fixed...
- kubanczyk 6y agoI wonder if there are some khem-khem notable clouds that just don't provide an old-school tty login. /s
- timeattack 6y agoIt's cool and interesting application of the technology, but doesn't really seem to be practical. When you're unable to access machine using your standard SSH keys usually it means that it's highly unlikely that it will be possible to login remotely via other means. As an emergency login there are two common options: * in case of cloud: use remote VM console provided by the hosting provider. * in case of bare-metal: use IPMI to access machine console directly.
- isatty 6y agoYep, the most common way I've lost access to machines is by messing up the iptables/ipfw rules. Read a post here about avoiding that by having a timed reset with sleep.
- leoh 6y agoLink?
- oars 6y agoThis has happened to me as well. Where could I read about this method?
- lazyant 6y agoFor people asking: you can create a resetfw.sh script, for iptables: #!/bin/bash iptables -P INPUT ACCEPT iptables -P FORWARD ACCEPT iptables -P OUTPUT ACCEPT iptables -t nat -F iptables -t mangle -F iptables -F iptables -X chmod +x resetfw.sh and add it for ex to /etc/cron.hourly directory This way you can test your iptables rules and they'll get clear at every hour. Once you check they are OK you can delete this cronjob. (NOTE: I'm typing from memory, haven't tested this)
- cbb330 6y agoWhy not use certificates as your primary authentication for SSH? Facebook has a great blog post on implementing this at scale: https://engineering.fb.com/security/scalable-and-secure-access-with-ssh/ https://engineering.fb.com/security/scalable-and-secure-acce...
- theatrus2 6y agoIf you’re on AWS and have credentials for users there, you can also run bless https://github.com/Netflix/bless https://github.com/Netflix/bless
- tashian 6y agoYes! Shameless plug — we (smallstep.com) offer a service that makes this frictionless at scale and super easy to set up. You'll never want to go back to public keys.
- alexandrerond 6y agoI'm very confused, given Yubikeys have smart card fuctionality and they can be used by gpg-agent to SSH with the regular gpg key (you can add to authorized_keys just like any other keys) and you don't have to go through this whole mess of setup to create a CA and install it. What am I missing?
- tashian 6y agoThat sounds like a great option too, depending on your situation. One difference is that the CA is on the hardware key, but the cert (and its private key) is not. Imagine you're on a team of 50, and anyone on the team might need emergency access to a host at some point. You wouldn't want to buy 50 keys and 50 safes. Just designate a couple folks to manage emergency access. They can manually mint a cert for a colleague as needed, and send it over a secure channel. No security key needed to use the cert, and it self-destructs after a few minutes.
- munchbunny 6y agoIt's a chicken and egg problem: if you can't SSH into the machine, how do you add your key to the SSH config on the target machine? You could use a very long lived key, but then as soon as you have multiple people who might need production SSH access, you've got access control and revocation issues. The SSH CA is a good minimal solution, because the CA can issue only short-lived SSH keys (few hours at a time) that you use once and throw away. Also, CA trust scales better because it moves user management burden to the certificate issuing process and removes the need to modify the SSH config every time you onboard a new user. It's a pretty standard practice. Here's a post from Facebook about it from several years ago. This post is just about how to do it using YubiKeys. https://engineering.fb.com/security/scalable-and-secure-access-with-ssh/ https://engineering.fb.com/security/scalable-and-secure-acce...
- harikb 6y agoThis can also work as a solution where the “setup” (of trusting CA) is baked in to the image. Then there is no ssh related setup until the day you actually need to ssh to the host. And you get the guarantee that no ssh login can happen until you issue a temp-pair. This is actually quite useful for deploying clusters of machines that one doesn’t want normal ssh access until there is a real need. I think this was also mentioned in another comment
- munchbunny 6y agoThis is a pedantic detail, but if you're trying to implement this system, it does matter: "resident key" is not a required feature here. You're not using the hardware token for its WebAuthn capability, you're using it for its smart card capability. You just need PKCS11 token support for SSH, which the YubiKey's smart card capability can do. YubiKey 4 and YubiKey FIPS can both do it, and so can regular old smart cards even though that form factor is a lot less popular now. The workflow is the same: generate a key pair on the hardware token, have the CA sign it, install the signed cert onto the hardware token, and then SSH with it.
- closeparen 6y agoThe procedure here is actually using WebAuthn, which is now explicitly implemented by OpenSSH.
- ausjke 6y agowhat about port knocking?
- jlgaddis 6y agoValid: from 2020-06-24T16:53:03 to 2020-06-24T16:03:03 Um...
- ed25519FUUU 6y agoHere's what I like to do on my server(s) in cron, which pulls my keys from github: @hourly <username> ssh-import-id gh:<github username> If I lose my keys to this host, I can simply update github.com with my new ones and go to lunch. I'll be able to login again shortly. And on all of my hosts: @reboot <username> ssh-import-id gh:<github username> This is REALLY helpful on devices like raspberry pi, where they may stay shutdown / offline for years. The minute they're powered up again they'll get my fresh keys and I can login to them without needing a console. http://manpages.ubuntu.com/manpages/bionic/man1/ssh-import-id.1.html http://manpages.ubuntu.com/manpages/bionic/man1/ssh-import-i...
- aaronmdjones 6y agoTo add to the blog post; you don't need brew or step or any of that nonsense to inspect certificates. $ ssh-keygen -Lf the-cert.pub
- dcow 6y agoYou can, but `ssh-keygen` is about as nice to use as `openssl` which practically means you spend a lot of time with your head in the manual. The `step` tools have a nicer UI: $ step ssh inspect the-cert.pub Also the post already mentions that using `step` instead of `ssh-keygen` is optional, so I'm not sure why you feel the need to repeat it...
- aaronmdjones 6y agoRight, you'd have to look up the switches in the manpage if you don't remember them, but that's already the case with the generation portion, which is why the post includes the switches for that. I'm just saying it could have included the inspect switches too.
- dcow 6y agoWe actually plan to update the post to demonstrate doing it entirely with the `step` tool. We just want to do a pass on the UX to make sure it is as easy an foolproof as possible before bringing more attention to it.
- markpeek 6y agoUsing certificates with SSH is the way to go for shared access servers. Here's an open source way (yes, I'm involved in the project) to manage authorization and access with asynchronous approvals: https://github.com/cloudtools/ssh-cert-authority https://github.com/cloudtools/ssh-cert-authority
- dcow 6y agoSmallstep also offers an open source ssh-aware kms-backed certificate authority. https://github.com/smallstep/certificates https://github.com/smallstep/certificates One nice advantage is its support for different provisioning flows. The oauth flavor allows you to hook into an existing identity provider to authenticate certificate requests. Simply: $ step ssh login and boom you've got a short-lived ssh certificate in your ssh-agent using a private key that never touched the disk.
- dmitrygr 6y agoWebsite unreadable on mobile. Commands cut off and not scrollable.