Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192731

Re: SSH session audit

From David Christensen <dpchrist@holgerdanske.com>
Newsgroups linux.debian.user
Subject Re: SSH session audit
Date 2018-02-19 22:40 +0100
Message-ID <vl1kd-8rM-7@gated-at.bofh.it> (permalink)
References <vkTmG-3qb-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 02/19/18 04:51, me@risca.eu wrote:
> Hi,
> 
> I'm co-managing a server with a friend of mine offering ourself some
>  basic service (like emails, file sharing, etc). At this time each of
> us can freely login on the server via ssh (we trust each others) for
> the daily administrative tasks.
> 
> I would like to improve the current set up by adding a layer of 
> certification and proofing of the ssh session, because if you know
> that you are recorded you'll be enforce to behave better. For this
> scope I've found many different possible solution, but quite complex
> to be implemented (like ssh proxy that records the session [1]), or
> too basic (like using /usr/bin/script). So far none of those that
> I've found satisfy me.
> 
> About that I remember that some time ago (maybe one or two years ago)
> I read a post on planet debian about such a method for session audit.
> It was suggesting as an easy to run solution for external consultant:
> the recording and encrypting of the remote session was performed
> without requiring any proxy, letting to store the session data on a
> dumb external host. From what I could remember I think that the idea
> was something like recording the session with script like utilities 
> (launched at session login), then periodically encrypting it with gpg
>  and publishing on a local folder or on a remote resource. This way
> the owner of the system could reliably access the session log, and
> the remote person could always prove what he did at during the ssh
> session.

That does not sound secure.  See the Byzantine Generals' Problem:

     https://en.wikipedia.org/wiki/Byzantine_fault_tolerance


> Do you know about that solution? Or could you suggest something
> similar?
> 
> Thank you,
> 
> risca.
> 
> [1] ssh proxy solutions: ssh-bastion, KeyBox


On 02/19/18 08:34, Roberto C. Sánchez wrote:
> You might want to consider a whitelist of commands accessible via
> sudo. Each access of sudo is logged by the system and if you do not
> permit the user modify system logs, then that may meet your
> requirements.

+1 for sudo (no comment on the rest).  This book is good:

     https://www.michaelwlucas.com/tools/sudo


David

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

SSH session audit me@risca.eu - 2018-02-19 14:10 +0100
  Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:20 +0100
    Re: SSH session audit me@risca.eu - 2018-02-19 14:40 +0100
      Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:50 +0100
  Re: SSH session audit Steve Kemp <steve@steve.org.uk> - 2018-02-19 14:50 +0100
  Re: SSH session audit john doe <johndoe65534@mail.com> - 2018-02-19 17:00 +0100
    Re: SSH session audit me@risca.eu - 2018-02-19 17:30 +0100
      Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 17:40 +0100
      Re: SSH session audit Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 17:40 +0100
  Re: SSH session audit David Christensen <dpchrist@holgerdanske.com> - 2018-02-19 22:40 +0100

csiph-web