4 ms·
Is that what I get out of the box using tailscale for ssh? https://tailscale.com/kb/1009/protect-ssh-servers/ https://tailscale.com/kb/1009/protect-ssh-servers
by michael_j_ward 5y ago
Is that what I get out of the box using tailscale for ssh?
https://tailscale.com/kb/1009/protect-ssh-servers/ https://tailscale.com/kb/1009/protect-ssh-servers/
- tener 5y agoTailscale (and other similar solutions) works on the network level. This is not a bad idea in itself, but SSH certs operate on the application level. The fact you can ping the server shouldn't mean you are allowed to actually access it.
- tptacek 5y agoTwo examples of things Tailscale doesn't give you for this usage model that SSH CAs can: * Transcript-level audit trails for what people are actually doing on SSH sessions. * Differential access to different groups of users to the same machines. Tailscale and SSH CAs work together nicely: require membership in the right Tailscale group to talk to SSH at all, thus tying access to SSH to your (e.g.) Google login and MFA requirement, and use something like Teleport for the actual SSH login, to get the audit log, group access, and an additional authentication factor.