<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Auth hopping Station in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4817303#M44589</link>
    <description>&lt;P&gt;Hi SEP,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the feedback, much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;D.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jul 2011 13:38:30 GMT</pubDate>
    <dc:creator>Duffster</dc:creator>
    <dc:date>2011-07-07T13:38:30Z</dc:date>
    <item>
      <title>SSH Auth hopping Station</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4814375#M44574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have approx 20 servers in my domain (mostly RHEL) and from an administration point of view I was thinking of using a dedicated server as a hopping station and setting up SSH authentication keys bewteen it and the other servers so as to enable me to gain easy/quick access to any server in the domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In doing so this will prevent me from logging into each box separately and having to&amp;nbsp;search for and enter in passwords every time I need to log in to a different server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;a) is this a good idea&lt;/P&gt;&lt;P&gt;&amp;nbsp;b) are there any security implications I need to consider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;D.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2011 16:24:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4814375#M44574</guid>
      <dc:creator>Duffster</dc:creator>
      <dc:date>2011-07-05T16:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Auth hopping Station</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4815825#M44582</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;The security restrictions come to play if you allow root password free access too or from this hopping system. PCI and Sox audits often take a dim view of root password free access. This system should at least not have any real production running on it. Carefully consider what systems it can access. If it can access a DMZ/PCI Island system, if you have any you could have audit problems. Overall, I think the plan improves security.&lt;BR /&gt;&lt;BR /&gt;I think it is a reasonable plan you have. You can close the firewall and prevent unauthorized system access. On the downside you have a single point of failure. If this system goes, a lot of potential work can not get done.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 06 Jul 2011 15:51:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4815825#M44582</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2011-07-06T15:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Auth hopping Station</title>
      <link>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4817303#M44589</link>
      <description>&lt;P&gt;Hi SEP,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the feedback, much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;D.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2011 13:38:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/ssh-auth-hopping-station/m-p/4817303#M44589</guid>
      <dc:creator>Duffster</dc:creator>
      <dc:date>2011-07-07T13:38:30Z</dc:date>
    </item>
  </channel>
</rss>

