Subject: Re: PermitRootLogin in SSHd (WAS: Re: Telnet logins)
To: Brian Seklecki <lavalamp@burghcom.com>
From: Andrew Doran <ad@netbsd.org>
List: port-i386
Date: 08/20/2001 07:42:02
Brian Seklecki <lavalamp@burghcom.com> wrote:

> Not to nitpick, but in a vacuum, you can ssh into a system as root, but
> in production, you would probably never want to permit anyone to do that
> (even/especically if you're using RSA/DSA key authentication).

What if you've got to look after more than one machine, or you've got more
than one administrator and you want to use ssh? Pretend for a second that
Kerberos never existed - what would you do then?

Andrew