[Gllug] Selective SSH logins

Nix nix at esperi.org.uk
Wed Aug 27 11:54:15 UTC 2008


On 27 Aug 2008, Daniel P. Berrange verbalised:

> On Wed, Aug 27, 2008 at 05:23:26AM +0100, Nix wrote:
>> That depends very much on your network topology. If your NFS servers and
>> clients are within the same trust boundary, or you only share non-
>> security-important state, and especially if you export read-only, I
>> can't see the problem.
>
> Sure, if you can guarentee that no Joe Random user can plug in an ethernet
> cable to their laptop,

If they do that they've *broken into my house* and have physical access
anyway.

>                        and you control who has root on every client on
> your network

Yeah, I don't allow random strangers with root into my house.

-- 
`Not even vi uses vi key bindings for its command line.' --- PdS
-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug




More information about the GLLUG mailing list