GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    graslander (graslander@mastodon.social)'s status on Monday, 18-Nov-2024 06:02:54 JST graslander graslander

    I made a small tutorial on how to set up key authentication with an OpenBSD server.
    #openbsd #vps

    https://www.graslander.online/index.php/disable-password-authentication-for-openssh/

    In conversation about 6 months ago from mastodon.social permalink
    • Embed this notice
      Solène :flan_hacker: (solene@bsd.network)'s status on Monday, 18-Nov-2024 06:02:53 JST Solène :flan_hacker: Solène :flan_hacker:
      in reply to

      @graslander at first, I thought you wrote about setting up a PKI on OpenBSD

      As you use keys to authenticate clients, you still rely on TOFU when connecting to the server, you have two solutions to solve this:

      - use SSH certificates to authenticate both clients and servers
      - use SSHFP DNS entries

      I covered the second system if you are interested https://dataswamp.org/~solene/2023-08-05-sshfp-dns-entries.html

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: dataswamp.org
        Solene'% : Authenticate the SSH servers you are connecting to
        In this article, you will learn how to use SSHFP DNS records in order to prevent TOFU when using SSH.
    • Embed this notice
      Solène :flan_hacker: (solene@bsd.network)'s status on Monday, 18-Nov-2024 07:40:53 JST Solène :flan_hacker: Solène :flan_hacker:
      in reply to
      • Mischa 🐡😎

      @mischa @graslander I never thought doing it this way :flan_aww:

      In conversation about 6 months ago permalink
    • Embed this notice
      Mischa 🐡😎 (mischa@exquisite.social)'s status on Monday, 18-Nov-2024 07:40:54 JST Mischa 🐡😎 Mischa 🐡😎
      in reply to

      @graslander nice! Changing the settings in rc.conf.local might be even easier:

      # rcctl set sshd flags -o PasswordAuthentication=no

      In conversation about 6 months ago permalink

      Attachments


    • Embed this notice
      Solène :flan_hacker: (solene@bsd.network)'s status on Monday, 18-Nov-2024 18:24:47 JST Solène :flan_hacker: Solène :flan_hacker:
      in reply to
      • Joel Carnat ♑ 🤪 :runbsd:
      • Mischa 🐡😎

      @joel @mischa @graslander on systemd you can override the service to change the ExecStart property to add arguments to it

      In conversation about 6 months ago permalink
    • Embed this notice
      Joel Carnat ♑ 🤪 :runbsd: (joel@piou.foolbazar.eu)'s status on Monday, 18-Nov-2024 18:24:48 JST Joel Carnat ♑ 🤪 :runbsd: Joel Carnat ♑ 🤪 :runbsd:
      in reply to
      • Solène :flan_hacker:
      • Mischa 🐡😎

      @solene @mischa neither did I.
      I keep editing the config file. Probably because that works on every OS.

      I wonder if/how that would work with SystemD based stuff.

      @graslander

      In conversation about 6 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.