i want to remotely ssh to my home server, and I was wondering if I could just forward port 22 with disabling password login and use pubkey authentication will be safe enough?

  • @gnordliB
    link
    fedilink
    English
    27 months ago

    If you are going all out, may as well add hosts.deny and hosts.allow.

    • @kaipeeB
      link
      fedilink
      English
      17 months ago

      Easy to do with known internal networks.

      Difficult to manage when roaming.

      • @gnordliB
        link
        fedilink
        English
        17 months ago

        Absolutely, just sometimes people forget those tools even exist. Of course, you can easily do the same thing with firewall rules as well.

        Also, that was a great tidbit about the pam email notification on successful logon. I haven’t seen that one before, thank you!!

    • @Kazer67B
      link
      fedilink
      English
      17 months ago

      Add port knocking, if we go all out, let’s go all out!