Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #199579
| From | Joe <joe@jretrading.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: SSH root login from one ip via certificate only, all other logins password only. |
| Date | 2018-08-29 14:50 +0200 |
| Message-ID | <ws853-7ZT-3@gated-at.bofh.it> (permalink) |
| References | <ws7Vn-7WD-1@gated-at.bofh.it> |
| Organization | JRE Trading Ltd |
On Wed, 29 Aug 2018 13:32:56 +0100 James Allsopp <jamesaallsopp@googlemail.com> wrote: > Hi, > I need to have one computer I can ssh to other computers as root for > Ansible. To do this I've set up a strong certificate with a password, > but what I want is to only be able to log in as root from one IP > using that cert. All other users should only log in via a password > and can do so from any IP. > > Currently normal user logins are broken with this sshd_config. Can > anyone tell me where I'm going wrong? Sudo is not an option. > I'd think it ought to be possible. Personally, I'd run two instances of sshd, it's pretty lightweight, and that would (probably) eliminate potential obscure bugs where the authors hadn't expected anyone to want to do this. -- Joe
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
SSH root login from one ip via certificate only, all other logins password only. James Allsopp <jamesaallsopp@googlemail.com> - 2018-08-29 14:40 +0200 Re: SSH root login from one ip via certificate only, all other logins password only. Joe <joe@jretrading.com> - 2018-08-29 14:50 +0200 Re: SSH root login from one ip via certificate only, all other logins password only. Dan Purgert <dan@djph.net> - 2018-08-29 15:20 +0200
csiph-web