Re: Security - Use of PasswordAuthentication by ltsp clients.
John Ellson <[email protected]>
| Newsgroups | gmane.linux.terminal-server.devel |
|---|---|
| Message-ID | <[email protected]> |
Scott Balneaves wrote:
> On Wed, Aug 27, 2008 at 09:28:34AM -0400, John Ellson wrote:
>
>> I have an ltsp server in an elementary/middle school with ltsp clients
>> on eth0 and (eventually) the public internet on eth1. I want to access
>> this machine from the internet for remote administration, so for
>> security I really need to be able to disable PasswordAuthentication, at
>> least on eth1, and use publickey authentication only. I'm particularly
>> concerned about this because of the weak passwords that the kids are
>> likely to use.
>>
>
> In general, I'd say connecting an LTSP box directly to the internet would be
> a "Bad Idea" (R)(TM), simply from the amount of securing you'd have to do on
> it. Keep in mind there's also inetd, nbd, possibly portmap (if you're running
> any NFS mounts), and if you've set up some kind of web portal on the box, then
> there's http to worry about, and the list goes on and onandonandonandon...
>
>
Fine. There is also a firewall. Thats not the issue. I still need
to remotely access this box by ssh,
so the firewall has ssh open.
--
John Ellson
-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_____________________________________________________________________
Ltsp-developer mailing list. To un-subscribe, or change prefs, goto:
https://lists.sourceforge.net/lists/listinfo/ltsp-developer
For additional LTSP help, try #ltsp channel on irc.freenode.net