Re: OpenSSH authorized keys

From: Solar Designer (solar@private)
Date: Sat Feb 16 2002 - 09:50:52 PST


On Sat, Feb 16, 2002 at 07:28:00AM -0800, shiftee wrote:

Hi,

> Considering Owl's primary focus is security, I was just wondering if you had
> considered disabling the 'PasswordAuthentication' option in OpenSSH (to
> prevent tunnelling of clear text passwords), and instead using authorized
> keys to increase security just that little bit more... ;-)

This isn't such an obvious choice even if your primary focus is
security.  Which authentication scheme is more secure depends on the
particular scenario.

The tunnelling of cleartext passwords is just _one_ of concerns with
one of these authentication schemes.  There're others, including some
that are specific to the public key based authentication schemes.

-- 
/sd



This archive was generated by hypermail 2.1.3 : Sun Jan 15 2006 - 13:43:16 PST