The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Deny root remote login help gonzotonka SUN Solaris 5 4 Weeks Ago 06:07 AM
how to deny someone to use ftp command ? yarx IP Networking 4 12-03-2007 09:46 PM
Deny root rlogin funksen AIX 4 01-25-2007 07:49 AM
ftp allow/deny list wbendek UNIX for Dummies Questions & Answers 1 06-09-2005 05:01 AM
Telnet deny sunbird UNIX for Dummies Questions & Answers 2 07-12-2004 01:49 PM

Closed Thread
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 11-16-2001
Registered User
 

Join Date: Nov 2001
Location: Maryland
Posts: 20
deny ssh from root - how to?

using redhat 7.2

Is it possible to not allow root to ssh into the server remotely, but allow the account that ssh'd in to the box to su to root? This way there is the added security of a hacker needing two passwords to hack your computer, a username/password for a regular account and also the root pass.

If so, is it really worth it, or am I wasting my time?
Forum Sponsor
  #2  
Old 11-16-2001
rwb1959's Avatar
Registered User
 

Join Date: Aug 2001
Location: Virginia, USA
Posts: 438
The short answer... YES.

You can simply not set up any "keys" in root's account.
If you can only log into the machine via ssh, only those
authorized users will have ssh capability (as themselves)
and can then "su" to root. Of course, if you have root access,
you can do anything you want including creating a ".ssh"
directory and place your own key into "authorized_keys"
thereby allowing ssh directly to root so you have to
set some policies up to make sure those with root access
do not violate them.
  #3  
Old 11-16-2001
PxT's Avatar
PxT PxT is offline
Registered User
 

Join Date: Oct 2000
Location: Sacramento, CA
Posts: 909
Just add "PermitRootLogin no" to your sshd_config file.
  #4  
Old 11-17-2001
Registered User
 

Join Date: Nov 2001
Location: Maryland
Posts: 20
thanks guys
Google The UNIX and Linux Forums
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 04:06 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0