news.volyx.in

How to SSH Properly (gravitational.com)

584 points by old-gregg · 2381 days ago · 158 comments on HN

Article summary

The article discusses best practices for securing SSH connections, including the use of SSH certificates, two-factor authentication, and bastion hosts. It provides a step-by-step guide on how to implement these security measures using OpenSSH. The article highlights the benefits of using SSH certificates, such as improved security and ease of use. By following these best practices, users can significantly improve the security of their SSH connections.

Main themes

  • SSH security
  • certificate-based authentication
  • bastion hosts
  • LDAP authentication
  • hardware security tokens
  • access control

What commenters say

  • Using SSH certificates is a good way to improve SSH security, but it has its own set of challenges, such as revocation of compromised certificates.
  • Some users prefer to use LDAP or other authentication methods instead of SSH certificates, citing ease of use and familiarity.
  • Implementing a bastion host can provide an additional layer of security and control over SSH access.
  • Short-lived certificates can be an effective way to manage access and reduce the risk of compromised credentials.
  • Some commenters argue that SSH certificates are not necessary for small-scale or low-risk environments, while others see them as a crucial security measure.
  • The use of hardware security tokens, such as Yubikeys, can provide an additional layer of security for SSH connections.
  • There are trade-offs between different authentication methods, including security, convenience, and scalability.