3 ms·
I'd recommend encrypting your private keys if needed with a pass-phrase. I'd also recommend still requiring a sudo password on the other end and sending auth ev
by voidlogic 11y ago
I'd recommend encrypting your private keys if needed with a pass-phrase. I'd also recommend still requiring a sudo password on the other end and sending auth events to a auditing server.
2 factor with a token is ideal, I suppose I should have added that to the list, but that is outside of feasibility for most users.
Still, for someone who doesn't have RSA tokens etc available, assuming your remote machine doesn't get owned and someone doesn't extract your pass-phrase with a wrench, that list makes for a very secure system.
- cbsmith 11y ago> I'd also recommend still requiring a sudo password on the other end and sending auth events to a auditing server. You should be auditing everything already, and adding in sudo now adds another attack vector. You also now have two different accounts that can be manipulated to compromise a system.