summaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorhttp://joeyh.name/2014-04-21 13:31:13 +0000
committeradmin2014-04-21 13:31:13 +0000
commiteb7497fd41f0b6d2f97e67f4e0a05fd7bb2b9350 (patch)
tree9da80abce9911b576bd123d55068c5b9771620f4 /doc
parent6e724af9f7d94df4bdb6958cd0313fb6e0e1b55c (diff)
Added a comment
Diffstat (limited to 'doc')
-rw-r--r--doc/todo/ssh__95__user_+_sudo/comment_1_3bc008e42587a3313f81ee740d7d80f0._comment10
1 files changed, 10 insertions, 0 deletions
diff --git a/doc/todo/ssh__95__user_+_sudo/comment_1_3bc008e42587a3313f81ee740d7d80f0._comment b/doc/todo/ssh__95__user_+_sudo/comment_1_3bc008e42587a3313f81ee740d7d80f0._comment
new file mode 100644
index 00000000..e0dc1d7f
--- /dev/null
+++ b/doc/todo/ssh__95__user_+_sudo/comment_1_3bc008e42587a3313f81ee740d7d80f0._comment
@@ -0,0 +1,10 @@
+[[!comment format=mdwn
+ username="http://joeyh.name/"
+ ip="209.250.56.214"
+ subject="comment 1"
+ date="2014-04-21T13:31:13Z"
+ content="""
+Running propellor that way would probably need ssh to allocate a tty in order for sudo's password prompt to work. And it adds complexity. Does it add security? I don't think so, PermitRootLogin=without-password or PasswordAuthentication=no is not going to let anyone brute force the root account.
+
+PermitRootLogin=forced-commands-only might be worth making easy to set up, so the only command that can be run with some special propellor-specific ssh key is propellor.
+"""]]