Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Feb 07, 2013 11:07 am 
Offline

Joined: Thu Feb 07, 2013 11:03 am
Posts: 1
We've just started using the managed beta and I have a suggestion to make. At present Linode require us to install their SSH key under the root user. As a matter of course we don't allow root login (and all other users are only permitted to log on with SSH keys - we don't allow passwords).

I would suggest it would be much more secure if Linode were to allow us to create a special "linode support" user and install their SSH key under that user. This would mean we wouldn't have to enable remote root access to our servers and any access would be properly audited to an identifiable user (which is particularly important if anyone is doing anything that touches the world of PCIDSS or other related standards).

[edit - forgot to say that obviously the linode support user would need to have sudo privileges, but that's still much more secure than just allowing root access]

If anyone from Linode is gathering feedback from the forums can you add this suggestion to the list?


Top
   
PostPosted: Thu Feb 07, 2013 2:10 pm 
Offline
Linode Staff

Joined: Sun May 01, 2011 1:36 pm
Posts: 9
adancy wrote:
We've just started using the managed beta and I have a suggestion to make. At present Linode require us to install their SSH key under the root user. As a matter of course we don't allow root login (and all other users are only permitted to log on with SSH keys - we don't allow passwords).

I would suggest it would be much more secure if Linode were to allow us to create a special "linode support" user and install their SSH key under that user. This would mean we wouldn't have to enable remote root access to our servers and any access would be properly audited to an identifiable user (which is particularly important if anyone is doing anything that touches the world of PCIDSS or other related standards).

[edit - forgot to say that obviously the linode support user would need to have sudo privileges, but that's still much more secure than just allowing root access]

If anyone from Linode is gathering feedback from the forums can you add this suggestion to the list?


This has been added to our list of features to consider. Thanks for the feedback!


Top
   
PostPosted: Fri Mar 15, 2013 9:54 am 
Offline
Linode Staff

Joined: Thu Jan 10, 2013 9:43 am
Posts: 11
Quote:
I would suggest it would be much more secure if Linode were to allow us to create a special "linode support" user and install their SSH key under that user. This would mean we wouldn't have to enable remote root access to our servers and any access would be properly audited to an identifiable user (which is particularly important if anyone is doing anything that touches the world of PCIDSS or other related standards).


Just an update - this has been implemented. You're able to specify both a user and a port that we can log in with, we just ask that you note these things in the provided fields and make sure we can sudo!


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group