Shared hosting SSH with public key authentication only
Summary
Manuel Schmitt describes switching off password-based SSH logins on shared hosting servers in favour of mandatory public keys. SSH was included free of charge in the web hosting packages. Since 23 October 2007, password logins on the shared hosting servers had been disabled.
Ideas
- Public key authentication removes reusable server passwords from the SSH login path.
- An additional activation step limits access to deliberately registered users.
- Technical hurdles can reduce abuse but must not simply lock out inexperienced users.
Insights
- Secure defaults work better than voluntary advice to many tenants.
- Access control should keep attackers out and support legitimate users with good documentation.
Facts
- Customers also had to apply for SSH access via a form.
Recommendations
- Allow modern key types and disable password authentication on the server side.
- Document key generation, rotation and what to do when a key is lost in an understandable way.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.