@scottalanmiller said in Fairly Hardened Jump Box:
@coliver said in Fairly Hardened Jump Box:
@Dashrender said in Fairly Hardened Jump Box:
@stacksofplates said in Fairly Hardened Jump Box:
Keys are required along with long password and OTP to get into system
And? So you're requiring Keys, a long password and One Time Passwords? Are you trying to protect the nuclear football?
I thought Scott normally stopped at using only keys? or was it keys and passwords.
I know he also recently setup Two Factor Authentication with Google Authenticator.
Keys and passwords are basically the same thing. A key is just a really long password.
But a password locked key is kind of different. Because it's two factor, a password you have AND one that you know. In some form, ALL forms of authentication are passwords. That's all a one time pin is, that's all biometric is, etc.
I guess I should have explained better. The key will be encrypted, but SSH will require the key and the system password also. So if you don't have the key it won't prompt you at all, but with the key then you enter your system password + the OTP.