  | | | restrict remote logins to service accounts. | restrict remote logins to service accounts. 2006-01-17 - By Michael Sobotta
Back We've had success creating accounts that are only able to sftp to a machine using a handy little program called rssh (http://www.pizzashack.org/rssh/). You will be able to configure this so your service accounts can only scp to a machine and not ssh and/or sftp.
__ ____ ____ ____ ____ ____ ____
From: taroon-list-bounces@(protected) [mailto:taroon-list-bounces@(protected)] On Behalf Of David.Knight@(protected) Sent: Tuesday, January 17, 2006 15:36 To: taroon-list@(protected) Subject: restrict remote logins to service accounts.
All, I have an issue with Admins/DBA's logging into my servers directly as service accounts such as user 'oracle'. I have had a hard time getting people to adopt the use of sudo. I am at the point where I need to restrict direct logins to these accounts. My goal is to force people to sudo to the service accounts from there assigned user account. I only allow ssh/scp connections to my servers. I have tried the sshd.config option "AllowUsers" but this also restricts scp logins. I can;t restrict this for automated processes run under the service accounts use scp. So the only thing I need to restrict is direct remote "ssh" logins. Any suggestions would be great.
-David Knight
-- Taroon-list mailing list Taroon-list@(protected) https://www.redhat.com/mailman/listinfo/taroon-list
|
|
 |