4 ms·
How is a ssh jumphost helping with rotating your keys? You still need to update the jumphost and all other servers with the new key right?
by ItsMrMe 6y ago
How is a ssh jumphost helping with rotating your keys? You still need to update the jumphost and all other servers with the new key right?
- orwin 6y agoI strongly disagree with the article, but: Have a yubikey to connect to your jumphost(we called that access vm), then have a cronjob that will, every month, deploy ansible, generate a key pair on the accessvm and deploy those new key on accessible vms (ideally not your log collecting vm, that should be even more secured.).
- jlgaddis 6y agoWere you using some awesome new cryptographically secure method to manage the passphrases of the newly generated keys (and communicate them to the user)? Or, more likely, were all of these new private keys granting access to all of your hosts just sitting there on disk unencrypted -- and, as a result, freely available to and easily stolen and used to gain access to all of your production machines by the first attacker to come along and compromise the bastion host?
- jasongill 6y agoI will never understand people who think a bastion host or "jump box" is a good idea. I've seen so many companies that have experienced extended downtime because they had an issue and it also broke their jumpbox - so nothing could be fixed until their bastion host was fixed. Plus, the companies I've bought that used bastion hosts ended up having the worst security on the jumpbox machine because it's a "set it and forget it" machine that isn't normally treated like a production server. I've seen bastion hosts that had root kits for years and nobody noticed because they never really logged in to look around at the bastion host itself. I've never understood the appeal, nor have I seen anyone do it well, honestly. It seems to get mentioned in all of these novice and semi-pro SSH related articles as a good idea and just makes my eye twitch when I see it.