On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • @[email protected]
    link
    fedilink
    213 days ago

    That server’s root access is now vulnerable to a compromise of the systems that have the private key.

      • @[email protected]
        link
        fedilink
        English
        102 days ago

        The client has the private key, the server has the corresponding public key in its authorized keys file.

        The server is vulnerable to the private key getting stolen from the client.

        • @[email protected]
          link
          fedilink
          12 days ago

          For ssh they both have private and public keys. The server could be at risk of having it’s own private key compromised if somebody breaks in, and vice versa a compromised client can lose its private key. The original wording made it sound like a compromised server would steal client keys.

          Also passworded keys are recommended

        • ☂️-
          link
          fedilink
          1
          edit-2
          2 days ago

          it is also vulnerable to whatever ssh exploits that can bypass the key

            • ☂️-
              link
              fedilink
              1
              edit-2
              2 days ago

              thats a good point. unless you forget to update it in a timely manner.

              that includes most servers out there ime, so