ssh private keys on our systems
Toshio Kuratomi
a.badger at gmail.com
Thu Sep 29 19:52:18 UTC 2011
On Thu, Sep 29, 2011 at 03:16:03PM -0400, seth vidal wrote:
> Hi,
>
> I'd like to put a new policy in place which goes something like this:
>
> If you upload your private keys (encrypted or not) we will remove them,
> then we will remove your public keys from FAS and force you to login and
> give a new one in FAS.
>
> We do the last step on the basis that your private key, being on a
> networked, multi-user machine is now exposed to the world and
> potentially compromised. So we can no longer trust it.
>
> thoughts?
>
+1
-Toshio
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url : http://lists.fedoraproject.org/pipermail/infrastructure/attachments/20110929/132e6203/attachment.bin
More information about the infrastructure
mailing list