Share.

6 Comments

  1. Carlos Delgado on

    Great article, you just saved a lot of time and problems to other developers of my company. Thank you so much !

  2. Michael Schwarz on

    Hi

    In the first part of your article, you state that allowing authentication as root over SSH creates a security risk. I’m inclined to call FUD on this. Could you elaborate on how this will lower the security of the system? In the setup you present, privilege escalation from the ubuntu to the root user is already possible without any further authentication.

    I would argue that enabling unrestricted sudo for an unprivileged user effectively grants root privileges to any process running as that user. Even an enabled password prompt from sudo can be trivially circumvented by placing a binary called `sudo` into the user’s ~/bin directory.

    Regards
    Michael

Exit mobile version