4 ms·
If you use pam_cracklib[1] or disable password based login for ssh, the only worry left over is working log rotation. [0] http://www.deer-run.com/~hal/sysadmin
by seven 15y ago
If you use pam_cracklib[1] or disable password based login for ssh, the only worry left over is working log rotation.
[0] http://www.deer-run.com/~hal/sysadmin/pam_cracklib.html http://www.deer-run.com/~hal/sysadmin/pam_cracklib.html
[1] http://lani78.wordpress.com/2008/08/08/generate-a-ssh-key-and-disable-password-authentication-on-ubuntu-server/ http://lani78.wordpress.com/2008/08/08/generate-a-ssh-key-an...
- dwc 15y agoI've had password auth disabled for many years, and it's quite liberating. Only a handful of times in all those years have I wanted to log in and not had a key handy. None of those times it was critical. It's interesting to listen to people give excuses about why disabling passwords is nice but won't work for them. None of them hold water, of course. Carrying physical keys for my house, car and office is a real pain. But I'm used to it and it's well worth what I get in return. So it is with ssh keys, but more so.