Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268425

Re: Root password strength

From Michael Kjörling <2695bd53d63c@ewoof.net>
Newsgroups linux.debian.user
Subject Re: Root password strength
Date 2024-03-20 13:20 +0100
Message-ID <Ik35f-oRu-1@gated-at.bofh.it> (permalink)
References (2 earlier) <IjOfT-fl7-5@gated-at.bofh.it> <IjWQ9-kZv-1@gated-at.bofh.it> <IjYRX-mcd-5@gated-at.bofh.it> <Ik1Zw-oei-9@gated-at.bofh.it> <Ik29b-ohH-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 20 Mar 2024 12:17 +0100, from tomas@tuxteam.de:
>>> For ssh use I issue secret keys to each user and maintain matching public
>>> keys in LDAP servers [...]
> 
>> So the private keys aren't private, thereby invalidating a lot of
>> assumptions inherent in public key cryptography.
> 
> We are using that schema in our (small) company, too. Private keys
> are definitely private here (we don't "issue keys" to anyone, everyone
> uploads their *public* keys to the LDAP).

Right; I have no issues with _that_ part. It's the _issuing_ of a
whole key pair that means that the private key _must_ have been
accessible to someone else at some point. In a scheme where the key
pair is generated by the user, the private key _may_ still be
accessible to others (for example through administrator access), but
that's a trade-off we always have to make when using a system
administered by someone else; and it can be mitigated by e.g. storing
the key on a SSH-capable Yubikey or in the TPM, along with a
decent-strength passphrase.


> Definitely. "Issuing keys" to people is a "crypto smell". I know,
> it is being done far too often. People are too stupid to make their
> key pairs, it is often said. But keeping people stupid is your
> biggest security hole!

Step 1: Open a terminal

Step 2: Run this command: ssh-keygen -f ~/.ssh/my_key_<date> ...

Step 3: Submit (through whatever means appropriate to the environment)
the contents of ~/.ssh/my_key_<date>.pub; do not ever, no matter what
anyone tells you, share the contents of ~/.ssh/my_key_<date>

Step 4: Update ~/.ssh/config to indicate IdentityFile ~/.ssh/my_key_<date>

It's not _that_ hard. I'm pretty sure pretty much anyone who can
meaningfully use SSH to start with can figure that out.

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 15:50 +0100
  Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 16:00 +0100
  Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-19 16:10 +0100
    Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 16:50 +0100
      Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 21:20 +0100
  Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 16:10 +0100
    Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-19 21:30 +0100
      Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 06:40 +0100
        Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 07:10 +0100
          Re: Root password strength tomas@tuxteam.de - 2024-03-20 08:40 +0100
        Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 08:50 +0100
          Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 12:10 +0100
            Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 12:20 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:20 +0100
            Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 12:30 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:10 +0100
              Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-20 13:40 +0100
            Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 14:30 +0100
              Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 14:50 +0100
  Re: Root password strength Marco Moock <mm@dorfdsl.de> - 2024-03-19 16:40 +0100
  Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-19 20:40 +0100
    Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 22:00 +0100
  Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:00 +0100
    Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 16:20 +0100
      Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-20 16:30 +0100
        Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:10 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:20 +0100
            Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:10 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:30 +0100
              Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
              Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 20:50 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 21:00 +0100
                Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 21:30 +0100
          Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 18:50 +0100
            Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:50 +0100
        Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-21 20:40 +0100
          Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-22 11:00 +0100
            Re: Root password strength Joe <joe@jretrading.com> - 2024-03-22 12:00 +0100
            Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-22 13:30 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 10:50 +0100
            Re: Root password strength Lee <ler762@gmail.com> - 2024-03-23 01:10 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 11:30 +0100
      Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:50 +0100
    Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:00 +0100
      Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:10 +0100
        Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 17:30 +0100
          Re: Root password strength Max Nikulin <manikulin@gmail.com> - 2024-03-20 17:50 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
            Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 18:40 +0100
              Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
                Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 19:20 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:40 +0100
                Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 21:20 +0100
                Re: Root password strength Curt <curty@free.fr> - 2024-03-21 17:50 +0100
                Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:40 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
        Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:30 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
        Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:20 +0100
      Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 17:10 +0100

csiph-web