LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices

Reply
 
LinkBack Search this Thread
Old 11-21-2005, 06:55 AM   #1
stinkpot
LQ Newbie
 
Registered: Nov 2005
Posts: 6

Rep: Reputation: 0
restrict server access by mac address?


hi all,

does anyone know if there's a way to restrict ssh/sftp logins using MAC address? i'm setting up a fileserver and i feel uncomfortable using usernames and passwords - those things are so easily shared.

thanks!
- ld
 
Old 11-21-2005, 03:29 PM   #2
Moloko
Member
 
Registered: Mar 2004
Location: Netherlands
Distribution: Debian
Posts: 729

Rep: Reputation: 30
Use iptables to allow specified MAC addresses to connect to the SSH port.
 
Old 11-21-2005, 05:14 PM   #3
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,698
Blog Entries: 1

Rep: Reputation: 374Reputation: 374Reputation: 374Reputation: 374
However, you should be aware that MAC addresses are not secure or stable. They aren't preserved as a packet traverses the Internet and they are trivial to spoof. If you want to restrict ssh access to specific machines, using key-based authentication is a much better idea.
 
Old 11-21-2005, 09:23 PM   #4
stinkpot
LQ Newbie
 
Registered: Nov 2005
Posts: 6

Original Poster
Rep: Reputation: 0
sorry - how exactly do i go about using key-based authentication? can windows users run something like ssh-keygen? (if you could even point me to an introductory website, i'd be much obliged.)
 
Old 11-22-2005, 07:05 AM   #5
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,698
Blog Entries: 1

Rep: Reputation: 374Reputation: 374Reputation: 374Reputation: 374
There is a very good tutorial in the LQ tutorials section. The writer used Slackware, but the commands should work on any distro. For Widows, if you did a full download of Putty, there is a key generation program that comes with it and instructions on how to set it up can be found on the Putty site (and you can always search and ask here if you run into trouble).

The only difficulty with the Putty keys is that it adds a lot of useless text that you have to remove and you need to put the key on a single line (remove all carriage returns). The ssh daemon is kind of picky about the key format in Linux, so you do have to be careful when editing the Putty generated key.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba: How to restrict access to server via MAC-address? johnny1959 Linux - Networking 5 03-27-2008 04:43 AM
Can I deny access based on mac or IP address with shorewall? enigma_0Z Linux - Networking 1 06-02-2005 04:15 PM
Restrict X server access using /etc/security/access.conf anand_kt Linux - General 0 04-22-2005 08:40 AM
DHCP Server MAC Address found, IP address not assigned wmburke Linux - Wireless Networking 17 11-17-2004 10:33 AM
couple C++ questions - mac address & last file access time. BrianK Programming 3 07-17-2002 03:17 AM


All times are GMT -5. The time now is 03:00 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration