|
|
|
|
|
by dozzie
3534 days ago
|
|
You got the thing backwards. It's not "too bad that sshd can't enforce keys"
of some property that happened to be missing in the key attackers got their
hands on. It's "too bad the HPC center staff didn't have tools good enough to
manage their servers". CFEngine and Puppet being two examples of such tools
the staff missed (or didn't know how to put into use in this case). |
|
My point is that in general it would be better to disable password auth and only use key based auth, but only if you could somehow guarantee that the users wouldn't do crazy things like use password-less keys. But as you can't do that on the server-side, what other options do you have?