Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Unix - Secure login alternatives???

Thread Tools
 
Search this Thread
 
Old 09 January 2003, 03:00 PM
  #1  
stevem2k
Scooby Regular
Thread Starter
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

Can't go wrong with ssh .

If it's access to multiple servers then only allow access to a 'gateway' machine and tie down the i/p's allowed access to that machine over the firewall. Make sure they have their own accounts and log everything.

F-Secure or Putty if you want windoze clients.


Steve
Old 09 January 2003, 03:02 PM
  #2  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Cheers Steve
Old 09 January 2003, 03:26 PM
  #3  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Talking

Google returned Chiark's home page with PUTTY download on it as one of the first 5 links! How did you manage that Chairk!
Old 09 January 2003, 03:42 PM
  #4  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Take a look at the SSH client for Windows on ssh.com, it contains a rather nice SCP client too. Don't know about licensing but it's free for personal use.

Steve.
Old 09 January 2003, 03:50 PM
  #5  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Steve

Already done that one mate, www.ssh.com, forwarded details to those that need it now.

Thanks, Alex
Old 09 January 2003, 04:08 PM
  #6  
chockymonster
Scooby Regular
 
chockymonster's Avatar
 
Join Date: Aug 2002
Posts: 577
Likes: 0
Received 0 Likes on 0 Posts
Post

You are better off going for the freeware /open source clients,
they are updated more regularly and are a lot better!

I use putty and winscp to access the boxes. All logins are done with secure certificates created on the unix boxes, so no passwords in site, just a passphrase.
In the past I've used a usb secure dongle to encrypt the area of the hard drive that the certificates are stored on. Just makes it a more secure environment.
Old 09 January 2003, 04:28 PM
  #7  
Andrewza
Scooby Regular
 
Andrewza's Avatar
 
Join Date: Jan 2002
Posts: 667
Likes: 0
Received 0 Likes on 0 Posts
Post

Same here, OpenSSH on UNIX, configured SSHv2 only, public key only and firewall restricted. Then putty on windows, obviously configured to use public key to login.
Old 09 January 2003, 05:51 PM
  #8  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Just using public key with no need for the user to enter a password or passphrase is no good for any serious security. You just shift the point of failure to the end users machine, where the public key is stored for anyone to use and gain access, if they do it from the same machine that then bypasses your firewall rules too. Always make them type something if the need for security is great.
Old 09 January 2003, 09:19 PM
  #9  
Andrewza
Scooby Regular
 
Andrewza's Avatar
 
Join Date: Jan 2002
Posts: 667
Likes: 0
Received 0 Likes on 0 Posts
Wink

Obviously keys should have a passphrase, perhaps I should be more verbose. For OpenSSH at least you have to actively choose not to have a passphrase with your keys as you're prompted to enter one on creation.
Old 10 January 2003, 10:27 AM
  #10  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

Yup, OpenSSH is a goodun
Old 10 January 2003, 10:44 AM
  #11  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Thanks guys
Old 10 January 2003, 11:23 AM
  #12  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

Any votes for Kerberized Secure Shell (ksh)?
Old 01 September 2003, 02:44 PM
  #13  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Question

Hi all,

We are looking at dropping Ace Server from RSA.
Now our only concern is remote users initial access to the unix systems.

SSH is going to be installed on all servers, so I guess all we need is a Windows version of SSH so that we can login in remotely via the VPN.

But what alternatives are there for secure logins to a unix system, perhaps using digital certificates?

Cheers, Alex

[Edited by DrEvil - 1/9/2003 2:45:09 PM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
BLU
Computer & Technology Related
11
02 October 2015 12:53 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
The Joshua Tree
Computer & Technology Related
30
28 September 2015 02:43 PM



Quick Reply: Unix - Secure login alternatives???



All times are GMT +1. The time now is 09:25 AM.