Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268426

Re: Root password strength

From Dan Ritter <dsr@randomstring.org>
Newsgroups linux.debian.user
Subject Re: Root password strength
Date 2024-03-20 13:40 +0100
Message-ID <Ik3oB-oXT-5@gated-at.bofh.it> (permalink)
References (2 earlier) <IjOfT-fl7-5@gated-at.bofh.it> <IjWQ9-kZv-1@gated-at.bofh.it> <IjYRX-mcd-5@gated-at.bofh.it> <Ik1Zw-oei-9@gated-at.bofh.it> <Ik2iR-okS-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


jeremy ardley wrote: 
> 
> On 20/3/24 19:03, Michael Kjörling wrote:
> > On 20 Mar 2024 15:46 +0800, fromjeremy.ardley@gmail.com  (jeremy ardley):
> > > [users are locked out from uploading their public key using ssh-copy-id]
> > So the private keys aren't private, thereby invalidating a lot of
> > assumptions inherent in public key cryptography.
> > 
> > Also, are you saying that you do not let users rotate their keys
> > themselves; and if so, why on Earth not?
> 
> 
> Private keys aren't private in any corporate network. Security management
> would be impossible to manage if users could generate their own keys and
> install them on any server. For one thing users do not have any easy way to
> revoke certificates.

No. Users create public/private keypairs, keep the private one
private and send you the public side to install on servers. A
user can revoke their own access by deleting the private one;
a sysadmin can revoke a user's access by deleting the public one
from each host that it's installed on.

For ssh, the sysadmin can also add/remove users from the
AllowUsers list in the sshd config, or add them to the DenyUsers
list, or remove their membership in an AllowGroups list.

Proponents of certificates are going to say "but this is harder
than adding their cert to the CRL", which is nominally true but
in practice, you most likely already have a distribution mechanism
for maintaining system configuration everywhere.

> In any serious network, private keys are simply a name for a secret key
> issued by an administrator to a user. Matching public keys are often
> published and are maintained by the administrator. Both keys are owned by
> the administrators.

This is incorrect, as Michael and others have stated.
 
> If you are in full control of your network and resources, sure, go ahead and
> rotate your keys. But if you are in a network run by others you have to
> accept their control of keys and access to resources.

No, you have to accept their control of access to their resources.

-dsr-

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 15:50 +0100
  Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 16:00 +0100
  Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-19 16:10 +0100
    Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 16:50 +0100
      Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 21:20 +0100
  Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 16:10 +0100
    Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-19 21:30 +0100
      Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 06:40 +0100
        Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 07:10 +0100
          Re: Root password strength tomas@tuxteam.de - 2024-03-20 08:40 +0100
        Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 08:50 +0100
          Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 12:10 +0100
            Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 12:20 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:20 +0100
            Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 12:30 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:10 +0100
              Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-20 13:40 +0100
            Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 14:30 +0100
              Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 14:50 +0100
  Re: Root password strength Marco Moock <mm@dorfdsl.de> - 2024-03-19 16:40 +0100
  Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-19 20:40 +0100
    Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 22:00 +0100
  Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:00 +0100
    Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 16:20 +0100
      Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-20 16:30 +0100
        Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:10 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:20 +0100
            Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:10 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:30 +0100
              Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
              Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 20:50 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 21:00 +0100
                Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 21:30 +0100
          Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 18:50 +0100
            Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:50 +0100
        Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-21 20:40 +0100
          Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-22 11:00 +0100
            Re: Root password strength Joe <joe@jretrading.com> - 2024-03-22 12:00 +0100
            Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-22 13:30 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 10:50 +0100
            Re: Root password strength Lee <ler762@gmail.com> - 2024-03-23 01:10 +0100
              Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 11:30 +0100
      Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:50 +0100
    Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:00 +0100
      Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:10 +0100
        Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 17:30 +0100
          Re: Root password strength Max Nikulin <manikulin@gmail.com> - 2024-03-20 17:50 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
            Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 18:40 +0100
              Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
                Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 19:20 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:40 +0100
                Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 21:20 +0100
                Re: Root password strength Curt <curty@free.fr> - 2024-03-21 17:50 +0100
                Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:40 +0100
                Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
        Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:30 +0100
          Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
        Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:20 +0100
      Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 17:10 +0100

csiph-web