On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • JasonDJ@lemmy.zip
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    edit-2
    9 days ago

    There must at least be MFA somewhere on the path then.

    Even just keys, I wouldn’t trust, unless they are stored on smartcards or some other physical “something I have”, require a PIN/passphrase. and centrally managed so they can be revoked and rotated. Too many people use unprotected SSH keys.