On Thu, 3 Jul 2003, Paul Bauer wrote:
> I personally don't allow ssh as root but am now curious as to why this
As most things, it depends on your point of view and what your goals and
requirements are. One argument is that it could remove accountability from
a specific user, as can any role account. Another point is that by
allowing root logins, a remote user could perform a brute force attack
against your root account. By restricting remote root access, the idea
is that you limit your root vulnerability to just local users.
andy
--
PGP Key Available at
http://www.tigerteam.net/andy/pgp
Received on Thu Jul 3 16:41:16 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:03:00 EDT
|