Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268413
| From | jeremy ardley <jeremy.ardley@gmail.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Root password strength |
| Date | 2024-03-20 08:50 +0100 |
| Message-ID | <IjYRX-mcd-5@gated-at.bofh.it> (permalink) |
| References | <IjIWR-b9R-15@gated-at.bofh.it> <IjJgd-bzk-13@gated-at.bofh.it> <IjOfT-fl7-5@gated-at.bofh.it> <IjWQ9-kZv-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On 20/3/24 13:32, tomas@tuxteam.de wrote: > How will a "VPN" with a "certificate" (whatever that means in this > context) be more secure than a SSH (assuming key pair authentication, > not password)? > > They are doing the same dance (key exchange, key pair validation, > session key establishment) -- the "certificate" part is just a step > further (and, BTW, SSH can do that, too), which just eases key > management (at the expense of security: you have but one more moving > part). > > The "port" thing stays the same: the VPN server uses a TCP > connection, too. > > Moving the port to a non-standard number, using fail2ban, firewall > knocking and those things don't increase security *directly* -- they > just remove noise from the logs, which eases the admin's task and > thus increase security indirectly. Benefits of running VPN rather that VPN + SSH or even just SSH: - VPN only has only one 'hole' in the firewall. - Providing VPN ingress through or to your firewall is a different security model to hosting a ssh server on your firewall. - Accessing an internal host using SSH from an internal machine is yet another security model. - A SSH server exposed to public will have less ability to detect and counter serious probes compared to a VPN server If you go for the arrangement I use, you need have only one security mechanism for all internal ssh servers and that mechanism will also defend in the event the firewall is breached. Then in isolation you can develop a security strategy for your public facing VPN ports as well as firewall configuration to mitigate any breach. Regarding certificates, I issue VPN certificates to be installed on each remote device. I don't use public key. For ssh use I issue secret keys to each user and maintain matching public keys in LDAP servers. SSHD servers can get the public keys in real time by using the AuthorizedKeysCommand. If a secret key is compromised I simply remove the matching public key. [users are locked out from uploading their public key using ssh-copy-id]
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 15:50 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 16:00 +0100
Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-19 16:10 +0100
Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 16:50 +0100
Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 21:20 +0100
Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 16:10 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-19 21:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 06:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 07:10 +0100
Re: Root password strength tomas@tuxteam.de - 2024-03-20 08:40 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 08:50 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 12:10 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 12:20 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:20 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 12:30 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:10 +0100
Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-20 13:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 14:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 14:50 +0100
Re: Root password strength Marco Moock <mm@dorfdsl.de> - 2024-03-19 16:40 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-19 20:40 +0100
Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 22:00 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:00 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 16:20 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-20 16:30 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:10 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:20 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:10 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 20:50 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 21:00 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 21:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 18:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:50 +0100
Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-21 20:40 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-22 11:00 +0100
Re: Root password strength Joe <joe@jretrading.com> - 2024-03-22 12:00 +0100
Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-22 13:30 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 10:50 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-23 01:10 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 11:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:00 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:10 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 17:30 +0100
Re: Root password strength Max Nikulin <manikulin@gmail.com> - 2024-03-20 17:50 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 18:40 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 19:20 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 21:20 +0100
Re: Root password strength Curt <curty@free.fr> - 2024-03-21 17:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:40 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:20 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 17:10 +0100
csiph-web