4 ms·
In SSH you can limit the login to a specific user or user with less permissions than root. Is that something your PAM module(s) would need to handle? e.g. Now
by 0xCMP 5y ago
In SSH you can limit the login to a specific user or user with less permissions than root.
Is that something your PAM module(s) would need to handle?
e.g. Now that you're authenticated via the IP, how do we authorize the login?
- xena 5y agoThat is something that I have yet to really figure out. I would love to have the ability to send an authz message to the machine connecting to that other machine, identd style. I also figure that this could also result in a GUI prompt to confirm it. Maybe root access over tailpam would need you to be a tailnet admin? I'm not totally sure. Still very much thinking this through. Either way this needs a lot of work to be super secure and useful, right now it's mostly a proof of concept that has taken FOREVER because debugging PAM is so painful. There's more to come in the future, but I fully expect this to be a bit of an uphill sell to people. Writing stuff that mucks with the authentication stack is rightfully kinda scary, and there will need to be a lot of security and subject matter expert review. I expect this to be a slow burn, but good god I would love to see it happen.
- 0xCMP 5y agoWell with ssh usually you need to configure which keys are allowed per user so maybe `~/.tailpam_authorized` with either user, group, or ip (similar to tailscale config) could control access per user. Alternatively, now that it's authenticated securely enabling password for authz could work maybe?
- pxc 5y ago> I fully expect this to be a bit of an uphill sell to people. Writing stuff that mucks with the authentication stack is rightfully kinda scary, and there will need to be a lot of security and subject matter expert review. I expect this to be a slow burn, but good god I would love to see it happen. Actually using it would be a long ways off, but I don't think conceptually it's a hard sell. I'm interested in making authentication easier for my developers lately, and also in dodging some key management in favor of accounts people already have at work. Right now, I'm evaluating Tailscale for VPN access, since I find myself supporting developers without (yet) any remote access to them or any endpoint management crap on their machines, and walking them through configuring WireGuard has proven painful (more painful than I expected, which maybe sounds dumb). (Incidentally, ‘Tailscale’ is a name I remembered as a possible VPN solution because I think your blog is good.) One of the things that's occurred to me during my testing is that if it could be as stunningly easy to configure as Tailscale, it'd be great to use some kind of SSH gateway that plugged into everyone's SSO instead of managing a bunch of SSH keys. Plus, being able to have admins confirm privilege escalation requests might make it easier for me to convince some higher-ups to give the developers I support sudo rights. There are products that support things like this, but I think the use case is a natural extension of what people are likely already using Tailscale for, and it would be a killer feature to integrate.