- From: Lamont Granquist <
>
- To:
- Subject: [chef] Re: Re: RE: Re: RE: Re: Securing Knife
- Date: Sat, 09 Nov 2013 11:19:24 -0800
If you're worried about keyloggers or remote control tools on
admin's workstations, then you've lost the war already.
There is a clear risk vector in stolen laptops and in drive-by
hacks of laptops snarfing unencrypted credentials.
Making knife encrypt the existing user.pem file would be fairly
easy.
Making knife, and the chef-server, use ssh identities and
integrate with ssh-agent would be very cool, but obviously more
work. Since Dan is doing work that will eliminate the need for
validation keys and leverage the user creds for provisioning
servers, if we could pick up existing ssh keys then that would
make chef a lot easier to use -- the signup process becomes "paste
in your public ssh key" which people should be trained to do from
interacting with AWS and other cloud services. That key starts to
be a lot of eggs in one basket, but for admins with root access,
compromise of their ssh credentials is usually enough to own the
entire shop anyway -- admin laptops should have encrypted drives
and use ssh-agent at that point.
On 11/7/13 9:43 PM, Ranjib Dey wrote:
"
type="cite">
i like the idea. i dont think it will be lot of
work to implement this. though i find the whole
password/ssh-agent/gnome bit strange (keyloggers? each tool will
add 1+ vector), but this will help in general 2 factor auth/
ldap backed etc.
|
- [chef] Securing Knife, Kemp, Joseph A. (JKEMP), 11/06/2013
- [chef] Re: Securing Knife, Mike, 11/06/2013
- [chef] RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/06/2013
- [chef] RE: Re: Securing Knife, Kadel-Garcia, Nico, 11/07/2013
- [chef] Re: RE: Re: Securing Knife, Julian C. Dunn, 11/07/2013
- [chef] RE: Re: RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/07/2013
- [chef] Re: RE: Re: RE: Re: Securing Knife, Ranjib Dey, 11/07/2013
- [chef] Re: Re: RE: Re: RE: Re: Securing Knife, Lamont Granquist, 11/09/2013
- [chef] RE: Re: Re: RE: Re: RE: Re: Securing Knife, Kadel-Garcia, Nico, 11/09/2013
- [chef] Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Phil Cryer, 11/09/2013
- [chef] Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Lamont Granquist, 11/10/2013
- [chef] RE: Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/18/2013
- [chef] Re: RE: Re: RE: Re: Securing Knife, Seth Falcon, 11/07/2013
[chef] Re: Securing Knife, Steffen Gebert, 11/10/2013
Archive powered by MHonArc 2.6.16.