On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • forbiddenlake@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 days ago

    The client has the private key, the server has the corresponding public key in its authorized keys file.

    The server is vulnerable to the private key getting stolen from the client.

      • x00z@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 days ago

        Finding an exploit in ssh is worth more than whatever your server has to offer though.