Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248104
| From | <tomas@tuxteam.de> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Unlocking (remote/local), was Re: Help with suid (bash) |
| Date | 2022-05-11 20:30 +0200 |
| Message-ID | <ElZfX-eOoI-9@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <ElAAV-ezOV-3@gated-at.bofh.it> <ElHj3-eDJa-1@gated-at.bofh.it> <ElKTE-eFZj-1@gated-at.bofh.it> <ElMLL-eH9t-35@gated-at.bofh.it> <ElX4t-eNbJ-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Wed, May 11, 2022 at 11:07:09AM -0500, David Wright wrote: [...] > But after two posts about background information on setuid shell > scripts, you now write "the worst antipattern is to misuse tech > to force people to follow some nonsensical rituals". Strong words. Sorry if I was unclear. The point I was trying to make is that OpenSSH allows you to change the behaviour we are discussing if you wish so. So it /doesn't/ follow that antipattern. As to the other points? Well: 0. if you want to be able to login directly as root, /and/ with a password, change the server's /etc/sshd_config 1. if you can be bothered to set up a key for root, use that (generally preferrable to 0.) 1a. you can even limit what a private key owner is able to do: e.g. "only backup". So even if someone manages to steal your remote backup's private key, (s)he'll only able to trigger a backup 2. if you don't like 0..1a, there's still sudo. You can fine-tune what commands (and what parameters go with those) each (local or remote) user is allowed to invoke, and even whether they're supposed to issue a password for that or they get it "password-less". What's not to like? What's missing? Cheers -- t
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200
csiph-web