0

Is it risky to open the SSH service on a web server (even with a strong password or with RSA keys) ? What are good practises to connect to a web server for maintenance ?

Thank you !

azea
  • 1
  • It's very common in *nix environments to open ssh on servers. Cloud services rely on it (how else could you manage hosted servers?) – Chris F Carroll Sep 05 '14 at 10:49
  • 2
    This is my favourite: https://security.stackexchange.com/questions/17931/possible-to-use-both-private-key-and-password-authentication-for-ssh-login - SSH key plus a 2FA token (you can use google authenticator on Android/iOS or windows Authenticator on windows phones... or get hardware tokens). – HocusPocus Sep 05 '14 at 10:53
  • Do you have a corporate VPN? Is your web server on it? – lzam Sep 05 '14 at 12:22

0 Answers0