Secure SSH connections the right way

Certified

Conclusions

SSH is not a perfect protocol, but in its simplest application, it at least provides basic measures against integrity loss. However, as IT security requirements grow, as stipulated in the industry, the protection provided by SSH out of the box can no longer be relied upon. Without key management and unambiguous integrity detection, SSH could become an opening for a cyberattack and can therefore compromise, the system-critical infrastructure. This problem can be remedied by centralized key management and independent integrity determination by a third-party entity.

Probably the most appropriate solution for many organizations, which because of its complexity this article does not cover, would be to combine SSH authentication with Active Directory (AD) authentication. The X.509 certificate-based authentication provided by AD is a perfect match. This system would also provide centralized identity management.

The Author

Simon Böhm wrote this article while completing his basic military service at the ICT & Cybersecurity Center of the Austrian Armed Forces. In private life, he focuses on general security strategies in network technology and software development.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Attacks on HTTPS Connections
    HTTPS protects a connection from both tapping and manipulation, but only if a man in the middle hasn't already infiltrated the Internet connection. We highlight the weaknesses in HTTPS and demonstrate how to protect your client and server.
  • Hardening network services with DNS
    The Domain Name System, in addition to assigning IP addresses, lets you protect the network communication of servers in a domain. DNS offers further hardening of network protocols – in particular, SSH fingerprinting and CAA records.
  • SSL/TLS best practices for websites
    SSL and TLS are very complex technologies. If you want to avoid wading through cryptography manuals to harden your HTTPS web server, read on for practical recommendations on establishing, securing, and optimizing your SSL/TLS configuration.
  • Transport Encryption with DANE and DNSSEC
    Those who think that enabling STARTTLS in the mail client will make their mail traffic more secure are wrong. Only those who bank on DANE can be sure that a mail server or a firewall will not switch off encryption in transit.
  • Secure your data channel with stunnel
    Stunnel provides a TLS wrapper with extensive configuration options to secure your data over insecure wireless networks.
comments powered by Disqus