Mailinglist Archive: opensuse (1986 mails)

< Previous Next >
Re: [opensuse] Results of moving ssh to a high port - Zero scriptkiddies in a 24 hour period.
  • From: James Knott <james.knott@xxxxxxxxxx>
  • Date: Fri, 28 Nov 2008 14:14:25 -0500
  • Message-id: <49304311.50505@xxxxxxxxxx>
Dominique Leuenberger wrote:
On 11/28/2008 at 1:47 PM, G T Smith

<grahamsmith@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Bob Williams wrote:

On Thursday 27 November 2008 15:03:29 David C. Rankin wrote:

James Knott wrote:

To turn off password checking, which of the following do I need to

modify

in sshd.config?


I am not sure this is a good idea. Just because you have moved the
default port to a different value does *not* mean you should disable
authentication. A more sophisticated scan is quite likely to

identify

I rather assume the user wanted to disabled password authentication in
favor of keybased authentication. If you read the thread in context,
this is at least what the story suggests.

I have this setup on my server and would not be afraid of it's
security.. or not more as with pw auth. Having keypair auth and no pass
sounds pretty good practice to me.

Dominique

Further, you can put a password on the key, so that even if someone
obtained it, they couldn't use it without knowing the password.


--
Use OpenOffice.org <http://www.openoffice.org>
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx

< Previous Next >