1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA512 |
3 |
|
4 |
Hans-Werner Hilse wrote: |
5 |
> Hi, |
6 |
|
7 |
Hi! |
8 |
|
9 |
> So I would definately prefer to always have a guaranteed working sshd |
10 |
> running (I find OpenVPN/telnet a bit strange and an unnecessary |
11 |
> potential security hole). |
12 |
|
13 |
If running permanently, then I agree, but I do not see the potential security hole if using a |
14 |
correctly designed/configured tunnel. |
15 |
|
16 |
> session. So you have to weight the risks. The real problem, however, |
17 |
> can only be overcome by another way to login. Firing up another |
18 |
> instance of sshd (on a different port) is just a matter of one simple |
19 |
> command, so I definately prefer that. |
20 |
|
21 |
As long as there is no issue with the sshd binary, of course :) |
22 |
|
23 |
- -- |
24 |
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica |
25 |
Servicios Ofrecidos: http://www.buanzo.com.ar/pro/ |
26 |
Unase a los Foros GNU/Buanzo - La palabra Comunidad en su maxima expresion. |
27 |
-----BEGIN PGP SIGNATURE----- |
28 |
Version: GnuPG v1.4.7 (GNU/Linux) |
29 |
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org |
30 |
|
31 |
iD8DBQFG7qOfAlpOsGhXcE0RCnGRAJ9fQIcJWbai4w/Daq81DPL1iEgaEgCfWkGg |
32 |
Apixlnkoih+SMOPShj6SpVA= |
33 |
=sBTB |
34 |
-----END PGP SIGNATURE----- |
35 |
-- |
36 |
gentoo-user@g.o mailing list |