[KLUG Members] ssh-keygen

bert klug at obbink.eu
Tue Mar 13 11:00:30 EST 2007


bill schreef:

> You can also require the server to respect rhosts.  If I understand that
> correctly, this means that not only does the login require a key (albeit
> without a password) it only accepts logins from your particular
> computer.
> 
Hmm, the advantage of rhosts is that it limits the access to certain known hosts. But any host-username combination in rhosts can user r commands, without the need for suppling a password.
Also there are some users accounts on the remote server that do not have a ssh-key on the local server, but can login thru ssh and need to supply username & password.

If there was a way to combine rhosts and ssh-key it should much safer. Eg. scp is only allowed to hosts that have a ssh-key.
But that's not a valid option I think...


Bert.




More information about the Members mailing list