It looks like you're new here. If you want to get involved, click one of these buttons!
I'm not asking for you guys to go into too many details, but just wondering how you guys handle this? I generally have a passwordless SSH key on my truecrypt drive that I use to get into one host, which works as my IRC/shell box and has a passworded key on it that lets me into the rest of my machines. Password auth disabled all around. I can't help but think there's a better way, but it's not coming to me at the moment?
Comments
The one key for all of your other machines is stored on a single account? Or am I missing what you described?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWell when you put it that way it just sounds plain insecure :P
Yes. Yes it is. I'm reinstalling a few of the machines and thought it was as good a time as any to rethink this.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksRoot, port 22 and ssh :P
I know, I'm Dale Maily.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@diffra, instead of putting the key on that box try ssh agent forwarding and keep the key on your physical machine.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanksthat's the new keychain i'm thinking about lately: http://www.cz.all.biz/img/cz/catalog/32259.jpeg
no kidding
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksJus store the key to all your machines on your desktop and you'll be fine.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThis guy knows data security. I believe him.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks1) Change SSH port 2) Disable all password logins 3) Private key/s on my Desktop (home computer) 4) Daily backup of ssh key/s to EncFS (encrypted) folder which gets backed up to Dropbox 5) ** If any servers need to communicate between each other, use public keys.
(Think I copied the setup from someone here or another server blog/forum).
PHP Looking Glass
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThat's pretty awesome.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksKeePass to store passwords, root, SSH, custom port (usually)
- Spam
- Abuse
- Troll
0 • Disagree Agree Thankshttp://sourceforge.net/projects/pacmanager/
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI connect to the SSH port (not 22) with PuTTY as root using a password like a real man ;)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI need to hack my servers every time I want to login, but I also have to patch the hole I used. I find that this keeps me in shape. /troll
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI use ssh w/ password on non-standard port and disabled root login, but thinking about using keyfiles soon... maybe storing them in a local truecrypt container. Putting the container in Dropbox is a nice idea, thanks!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksLike a bosssss!!!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksIf you put a passphrase on your key, there's not much point to storing them in yet another passphrase (TrueCrypt/etc)...
Now pretending to be a Mexican!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSSH Password w/ KeePass
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks