Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why disallow root login? What's wrong with allowing root login via public key only? Or via a public key limited by command="..."?


It's good practise first login as another user and then gain root priv's. This is auditable and if your sshd won't allow root login's, the can't be brute forced directly.


Do you ever need root login?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: