LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-23-2015, 02:48 AM   #1
lobezn0
LQ Newbie
 
Registered: Jan 2015
Posts: 2

Rep: Reputation: Disabled
What do you think of this "SSH setup"?


Hi,

I've been assigned to a new client where I got really surprised by the fact that, by default, they set SSH passwordless login for the root user between ALL servers they have installed, even between non-pro and pro boxes.

What do you think of this setup? IMO it's obviously insecure because if somebody gains access to one of the servers he can basically move around all the environment...
 
Old 01-23-2015, 02:52 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
That would never survive any security audit.

All you can do is strongly recommend that this be changed, however if "the business" is willing to accept the risks then it's their network, their rules.
 
1 members found this post helpful.
Old 01-23-2015, 03:17 AM   #3
lobezn0
LQ Newbie
 
Registered: Jan 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
I'll do that.

Thanks.
 
Old 01-23-2015, 05:24 AM   #4
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Depending on how few servers are (this works better the more servers there are), you could suggest using Kerberos authentication instead of having keys all over the place.

That way there would be only one private key per system, and no general sharing except via the KDC. You get the equivalent, but with better auditing, and less administrative overhead.
 
Old 01-24-2015, 09:43 AM   #5
Miati
Member
 
Registered: Dec 2014
Distribution: Linux Mint 17.*
Posts: 326

Rep: Reputation: 106Reputation: 106
I wouldn't be suprised if it's setup that way because it was the one that worked.
Since it works, apply a "don't fix if it ain't broke policy."

Maybe find out what is really needed & identify some ways to fine tune it?
I wrote some examples of setups.

This book is really good as well
(You know you want to support the OpenSSH team)
 
Old 01-24-2015, 01:13 PM   #6
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Quote:
Originally Posted by Miati View Post
I wouldn't be suprised if it's setup that way because it was the one that worked.
Since it works, apply a "don't fix if it ain't broke policy."

Maybe find out what is really needed & identify some ways to fine tune it?
I wrote some examples of setups.

This book is really good as well
(You know you want to support the OpenSSH team)
The problem is that if any ONE system does get broken into, ALL have to be considered broken into.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh session "disconnects" after "route add default ppp0", any suggestion? pettha Linux - Networking 2 09-15-2014 04:38 AM
[SOLVED] Don't understand how to use SSH keys with "ssh" and "scp" commands on Lubuntu maples Linux - Newbie 12 03-10-2014 10:09 PM
[SOLVED] LM13, How to setup bridge? USB wlan1 -->wireless eth1 / ad-hoc "hotspot"? / "ICS" ? Scott1265 Linux - Wireless Networking 1 05-08-2013 11:15 AM
SSH "walkie-talkie" setup, is it possible? PhoenixAndThor Linux - Networking 6 04-05-2012 04:21 PM
"mythtv-setup" giving "Session management error: Authentication Rejected" Mitchua Ubuntu 0 10-09-2005 04:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration