umeHack social
  • FAQ
  • Login
GNU social-nod för Umeå Hackerspace. Inbjudan krävs, men det är bara att hojta till oss om du vill vara med!
  • Public

    • Public
    • Groups
    • Popular
    • People

Conversation

Notices

  1. Infected Moomin (moonman@shitposter.club)'s status on Monday, 25-Nov-2019 18:23:26 CET Infected Moomin Infected Moomin
    Remote profile options...
    • Infected Moomin
    configured ssh two-factor authentication using yubikey. works pretty well. Factors are yubikey OTP and password. No way to use SSH key in two-factor ssh setup, it just overrides everything as the only factor.
    In conversation about a year ago from shitposter.club permalink
    • Infected Moomin (moonman@shitposter.club)'s status on Monday, 25-Nov-2019 18:27:28 CET Infected Moomin Infected Moomin
      Remote profile options...
      @opal hm, when I enabled it it just disabled the other factors.
      In conversation about a year ago permalink
    • Infected Moomin (moonman@shitposter.club)'s status on Monday, 25-Nov-2019 18:28:52 CET Infected Moomin Infected Moomin
      Remote profile options...
      @opal that's ok, this way is good enough for government work.
      In conversation about a year ago permalink
    • Nobody [LinuxWalt (@lnxw48a1)] (lnxw48a1@nu.federati.net)'s status on Monday, 25-Nov-2019 18:33:19 CET Nobody [LinuxWalt (@lnxw48a1)] Nobody [LinuxWalt (@lnxw48a1)]
      Remote profile options...
      in reply to
      @moonman Because: Yo[u] [will] b[e] [in] Key [oto] [soon].
      In conversation about a year ago permalink
      Infected Moomin likes this.
    • Infected Moomin (moonman@shitposter.club)'s status on Monday, 25-Nov-2019 18:55:30 CET Infected Moomin Infected Moomin
      Remote profile options...
      in reply to
      Another limitation seems to be that when enabled, every user must have a yubikey. This is a real problem if there's automated processes accessing the server over SSH.

      One way around this may be to run a second ssh server configured separately.
      In conversation about a year ago permalink
    • Infected Moomin (moonman@shitposter.club)'s status on Monday, 25-Nov-2019 19:49:37 CET Infected Moomin Infected Moomin
      Remote profile options...
      • :8b_d:‍:8b_i:‍:8b_e:‍:8b_l:‍:8b_a:‍:8b_n:
      @dielan yeah I'm already anticipating this being a huge pain in the ass. But it's required to pass our PCI compliance audit.
      In conversation about a year ago permalink
    • Mikael (mikael@social.umeahackerspace.se)'s status on Tuesday, 26-Nov-2019 05:40:43 CET Mikael Mikael
      in reply to
      Se have mfa requirements at work as well. Right now we have our private keys in yubikey and unlock them to ssh agent every 12 hours. Sudo is done with agent passing (ssh -A) . We are looking into transitioning to signed ssh keys and hashicorp vault.
      In conversation about a year ago permalink
      Infected Moomin likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

umeHack social is a social network, courtesy of Umeå Hackerspace. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All umeHack social content and data are available under the Creative Commons Attribution 3.0 license.