3 ms·
Also ssh supports "from" stanza, which allows you to limit networks from where you can login. Ideally it should set to either corporate network (and make people
by avaika 6y ago
Also ssh supports "from" stanza, which allows you to limit networks from where you can login. Ideally it should set to either corporate network (and make people to vpn to your corporate perimeter before going ssh) or to your home ISP range (if you're not a company). It's not a replacement for key rotation, but significantly reduces probability of described case.
- jlgaddis 6y ago> Also ssh supports "from" stanza, which allows you to limit networks from where you can login. Additionally, sshd supports "Match", which can limit where any or all of your users can log in from. There's also "AuthenticationMethods publickey", "PasswordAuthentication no", and "PermitRootLogin no", all of which one should also be using -- ideally, on top of (both host- and network-based) access lists / firewall rules preventing access to 22/TCP from everywhere except the hosts and/or networks you've explicitly permitted.