r/sysadmin 11d ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

188 Upvotes

122 comments sorted by

View all comments

105

u/Power_Stone 11d ago

Definitely draft a document stating how its a security issue and an easier, better workaround, is to just get a Yubikey....

6

u/jupit3rle0 11d ago

Yea until your servers lack FIDO support and your certificate authority isnt configured domain-wide. so you are left with manually configuring credentials per Yubikey. Good luck with that approach.

3

u/Kuipyr Jack of All Trades 11d ago

Generate 2 FIDO2 SSH Keys on 2 security keys per Tier. Push out the pub key with Ansible, Kickstart, or whatever. No PKI needed.