Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268423
| From | jeremy ardley <jeremy.ardley@gmail.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Root password strength |
| Date | 2024-03-20 12:30 +0100 |
| Message-ID | <Ik2iR-okS-1@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <IjJgd-bzk-13@gated-at.bofh.it> <IjOfT-fl7-5@gated-at.bofh.it> <IjWQ9-kZv-1@gated-at.bofh.it> <IjYRX-mcd-5@gated-at.bofh.it> <Ik1Zw-oei-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 20/3/24 19:03, Michael Kjörling wrote: > On 20 Mar 2024 15:46 +0800, fromjeremy.ardley@gmail.com (jeremy ardley): >> Regarding certificates, I issue VPN certificates to be installed on each >> remote device. I don't use public key. > What exactly is this "certificate" that you speak of? In typical > usage, it means a public key plus some surrounding metadata, but you > say that you "don't use public key". Each client is issued with a private key unique to the access point. When I say I don't use public key I mean I don't use certificates issued from public key authorities such as comodo >> For ssh use I issue secret keys to each user and maintain matching public >> keys in LDAP servers. SSHD servers can get the public keys in real time by >> using the AuthorizedKeysCommand. If a secret key is compromised I simply >> remove the matching public key. >> >> [users are locked out from uploading their public key using ssh-copy-id] > So the private keys aren't private, thereby invalidating a lot of > assumptions inherent in public key cryptography. > > Also, are you saying that you do not let users rotate their keys > themselves; and if so, why on Earth not? Private keys aren't private in any corporate network. Security management would be impossible to manage if users could generate their own keys and install them on any server. For one thing users do not have any easy way to revoke certificates. In any serious network, private keys are simply a name for a secret key issued by an administrator to a user. Matching public keys are often published and are maintained by the administrator. Both keys are owned by the administrators. If you are in full control of your network and resources, sure, go ahead and rotate your keys. But if you are in a network run by others you have to accept their control of keys and access to resources.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 15:50 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-19 16:00 +0100
Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-19 16:10 +0100
Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 16:50 +0100
Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 21:20 +0100
Re: Root password strength Greg Wooledge <greg@wooledge.org> - 2024-03-19 16:10 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-19 21:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 06:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 07:10 +0100
Re: Root password strength tomas@tuxteam.de - 2024-03-20 08:40 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 08:50 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 12:10 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 12:20 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:20 +0100
Re: Root password strength jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-20 12:30 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 13:10 +0100
Re: Root password strength Dan Ritter <dsr@randomstring.org> - 2024-03-20 13:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 14:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 14:50 +0100
Re: Root password strength Marco Moock <mm@dorfdsl.de> - 2024-03-19 16:40 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-19 20:40 +0100
Re: Root password strength debian-user@howorth.org.uk - 2024-03-19 22:00 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:00 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 16:20 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-20 16:30 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:10 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:20 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:10 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 20:50 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 21:00 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-20 21:30 +0100
Re: Root password strength <tomas@tuxteam.de> - 2024-03-20 18:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:50 +0100
Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-21 20:40 +0100
Re: Root password strength Jan Krapivin <daydreamer199005@gmail.com> - 2024-03-22 11:00 +0100
Re: Root password strength Joe <joe@jretrading.com> - 2024-03-22 12:00 +0100
Re: Root password strength "Alexander V. Makartsev" <avbetev@gmail.com> - 2024-03-22 13:30 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 10:50 +0100
Re: Root password strength Lee <ler762@gmail.com> - 2024-03-23 01:10 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-23 11:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 16:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:00 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 17:10 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 17:30 +0100
Re: Root password strength Max Nikulin <manikulin@gmail.com> - 2024-03-20 17:50 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 18:40 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:50 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 19:20 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:40 +0100
Re: Root password strength Jeffrey Walton <noloader@gmail.com> - 2024-03-20 21:20 +0100
Re: Root password strength Curt <curty@free.fr> - 2024-03-21 17:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 19:40 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 19:50 +0100
Re: Root password strength John Hasler <john@sugarbit.com> - 2024-03-20 17:30 +0100
Re: Root password strength Pierre-Elliott Bécue <peb@debian.org> - 2024-03-20 18:00 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 19:20 +0100
Re: Root password strength Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-20 17:10 +0100
csiph-web