4 ms·
One thing I've never understood is the point behind denying root login if you're enforcing key-based auth The administrator then has to do one of a) remember/m
by piggity 15y ago
One thing I've never understood is the point behind denying root login if you're enforcing key-based auth
The administrator then has to do one of
a) remember/manage a root password for su
b) remember/manage a user password for sudo
c) use passwordless sudo
What is the advantage?
Or is it just a hang-over from the telnet days where capturing the connection header was simple and thus preventing root login stopped the capturer from getting the root password at the start of the session?
- daten 15y agoThe admin should be logging in as a standard user with sudo access and using sudo for any administrative tasks anyway. This minimizes how much code is running priviledged, it also allows his actions to be audited because they're all logged. Additionally, if he's using key-based authentication, that key should still be encrypted so it can't be stolen and used by someone with unauthorised access to his filesystem. So he still has to remember the password to unlock his key when he fires up ssh-agent.