-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
,--- H S writes:
| Hello,
Hi,
[...]
| And, if that policy is wrong, the more tricky part, how do I start to
| convince them that outgoing SSH should be allowed ... which is going to
| be very uphill task. But since I find this policy huge pain in the neck
| (can't use rsync over ssh, can't use plain rsync even!), I am going to
| give it my best shot.
You can secure SSH, by, allowing only public key authentications from
external world, by using things like denyhosts[1] (which require
tcp_wrappers support in sshd), or running SSH on different port
(security by obscurity) . In OpenSSH 2.5p1 and later they've
introduced a "Match" block, where you can customize SSH configuration
on some criteria, for more information check out sshd_config(5) .
References:
[1] -
http://denyhosts.sourceforge.net/
| thanks,
| -> HS
HTH
- --
Ashish Shukla आशीष शुक्ल
http://wahjava.wordpress.com/
·-- ·- ···· ·--- ·- ···- ·- ·--·-· --· -- ·- ·· ·-·· ·-·-·- -·-· --- --
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHQyRJHy+EEHYuXnQRAiLHAJsE5xLqpkDQmvm919iJEo ajn+NuagCg5nd8
HM0WgqW94T0IOiMayNApbsY=
=uoVg
-----END PGP SIGNATURE-----