On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • miss_demeanour@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 days ago

    ffs…am I dealing with children here?
    You’ve accessed your server as a user, and then you su - to root.
    You don’t need a phone or a yubi or a dreamcatcher, or a unicorn.
    Please stop with your pretension.
    You’re so far out of your league that it’s embarrassing to me that I’ve bothered to answer.

    • JasonDJ@lemmy.zip
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      7 days ago

      There must at least be MFA somewhere on the path then.

      Even just keys, I wouldn’t trust, unless they are stored on smartcards or some other physical “something I have”, require a PIN/passphrase. and centrally managed so they can be revoked and rotated. Too many people use unprotected SSH keys.