LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-07-2004, 10:18 AM   #1
TheOneKEA
Member
 
Registered: Oct 2003
Distribution: Debian GNU/Linux 11 (amd64) w/kernel 6.0.15
Posts: 299

Rep: Reputation: 30
Securing a system and its SSH install for access from the outside


I have OpenSSH v3.6.1p2-19 installed into a Fedora Core 1 distro on my firewall machine. I currently have RSA passphrases set up and can SSH into the machine easily.

Is there a good online source of information on how to secure this machine's SSH installation so that I can unblock incoming connections to port 22 in my firewall, and allow me to SSH into my machine from the Internet?

I can provide the configuration files on request.
 
Old 07-07-2004, 10:41 AM   #2
qwijibow
LQ Guru
 
Registered: Apr 2003
Location: nottingham england
Distribution: Gentoo
Posts: 2,672

Rep: Reputation: 47
just update, make sure you are running the very latest secure version.
also, chnage the default setup so the server does not run as root, and only has access it needs.
 
Old 07-07-2004, 10:59 AM   #3
TheOneKEA
Member
 
Registered: Oct 2003
Distribution: Debian GNU/Linux 11 (amd64) w/kernel 6.0.15
Posts: 299

Original Poster
Rep: Reputation: 30
Quote:
Originally posted by qwijibow
just update, make sure you are running the very latest secure version.
also, chnage the default setup so the server does not run as root, and only has access it needs.
Thanks for the tip. Is there a specific version of OpenSSH I should install?
 
Old 07-07-2004, 11:11 AM   #4
iainr
Member
 
Registered: Nov 2002
Location: England
Distribution: Ubuntu 9.04
Posts: 631

Rep: Reputation: 30
Take a look at www.openssh.org. v3.8.1p1 looks like the latest.
 
Old 07-07-2004, 03:27 PM   #5
TheOneKEA
Member
 
Registered: Oct 2003
Distribution: Debian GNU/Linux 11 (amd64) w/kernel 6.0.15
Posts: 299

Original Poster
Rep: Reputation: 30
Question

Thanks, I'll have a look.

BTW, I'm having a bit of trouble with ssh-agent. I use graphical logins on my Red Hat 9 machine, and I have an .Xclients file which does the following to start my windowing environment, XFce 4:

Code:
#!/bin/bash
[ -x /usr/bin/ssh-agent -a -z "$SSH_AGENT_PID" ] && \
exec /usr/bin/ssh-agent /usr/bin/startxfce4 || exec /usr/bin/startxfce4
Yet ssh-agent never gets started. I and it said that if a commandline is given to ssh-agent, it will shut down when the command in the commandline shuts down - yet I don't see it in the process list after login. Any ideas?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Wierd happenings when securing SSH mattp Linux - Security 13 10-07-2005 07:00 AM
Securing SSH ZilverZtream Linux - Security 5 12-10-2004 03:33 PM
securing ssh robberttheman Linux - Security 8 08-27-2004 07:36 AM
Securing SSH tarballedtux Linux - Security 3 11-16-2002 04:45 AM
Securing root access vcheah Linux - Security 6 12-23-2001 03:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration