OldSalt
06-24-04, 08:37
We recently did a test install of H-Sphere 2.4 on a FreeBSD 4.9 box and were puzzled by the requirement for root login in ssh.
I understand that specifying "PermitRootLogin without-password" tightens up security a bit by requiring a shared key and that the firewall can limit ssh access to the box, but why is root login required at all? Is there a reason why H-Sphere cannot login as an unpriviledged user and su to root?
Also I read in one of the security threads (http://www.forum.psoft.net/showthread.php?t=7132) that one should Disable Remote Root Login which seems to contradict the root login via ssh requirement.
Can anyone clarify this for me?
Thanks.
I understand that specifying "PermitRootLogin without-password" tightens up security a bit by requiring a shared key and that the firewall can limit ssh access to the box, but why is root login required at all? Is there a reason why H-Sphere cannot login as an unpriviledged user and su to root?
Also I read in one of the security threads (http://www.forum.psoft.net/showthread.php?t=7132) that one should Disable Remote Root Login which seems to contradict the root login via ssh requirement.
Can anyone clarify this for me?
Thanks.