Remote Login (OpenSSH)
OpenSSH is a popular choice for secure, remote access to Unix hosts. The Secure Shell protocol provides secure authentication and session encryption services for remote login. These are the same services that a Kerberized telnet or rlogin provides, but Secure Shell doesn’t require a centralized infrastructure, like Kerberos; it only requires users to use one program (the Secure Shell client) to access a SSH server, and finally only communicates on one network port (as opposed to Kerberos, which requires a client to have direct access to both the Kerberos KDC and application server). Therefore, Secure Shell is a popular option for remote access to servers due to its simplicity in operation and small network footprint; its popularity has spawned many interoperable implementations of the protocol for most platforms available today.
OpenSSH is one of these implementations, an open source implementation developed by the OpenBSD group based upon the last unencumbered source code release of the original Secure Shell code.
Secure Shell uses public key encryption methods to perform mutual authentication and negotiation of a symmetric key for session encryption. Since Secure Shell does not require use of a centralized authentication source or signed public keys, it is inherently subject to man-in-the-middle attacks (hence the warnings when connecting to a server for the first time, or when the server’s key changes).
Now, with all of that said, how can we use Kerberos ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access