<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi-admin verify and ssh key-based authentication in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Multi-admin-verify-and-ssh-key-based-authentication/m-p/455593#M44039</link>
    <description>&lt;P&gt;We typically use ssh key-based authentication in our environment for the increased security over password auth. I'm looking into setting up Multi-admin verification for things like volume deletes. However in testing, I noticed that any admin can change any others' public keys, and therefore log in as any other MAV admin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, MAV creates a rule to restrict "security login password", but not to restrict "security login publickey", and you can't add such a rule either:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; security multi-admin-verify rule create -operation "security login publickey" -query "-multi-admin-approver true -different-user true"

Error: command failed: Operation "security login publickey" is not supported by this feature.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems like a huge hole, or am I misunderstanding something here?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 16:23:21 GMT</pubDate>
    <dc:creator>LieuentantLefse</dc:creator>
    <dc:date>2024-10-03T16:23:21Z</dc:date>
    <item>
      <title>Multi-admin verify and ssh key-based authentication</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Multi-admin-verify-and-ssh-key-based-authentication/m-p/455593#M44039</link>
      <description>&lt;P&gt;We typically use ssh key-based authentication in our environment for the increased security over password auth. I'm looking into setting up Multi-admin verification for things like volume deletes. However in testing, I noticed that any admin can change any others' public keys, and therefore log in as any other MAV admin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default, MAV creates a rule to restrict "security login password", but not to restrict "security login publickey", and you can't add such a rule either:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; security multi-admin-verify rule create -operation "security login publickey" -query "-multi-admin-approver true -different-user true"

Error: command failed: Operation "security login publickey" is not supported by this feature.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems like a huge hole, or am I misunderstanding something here?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 16:23:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Multi-admin-verify-and-ssh-key-based-authentication/m-p/455593#M44039</guid>
      <dc:creator>LieuentantLefse</dc:creator>
      <dc:date>2024-10-03T16:23:21Z</dc:date>
    </item>
  </channel>
</rss>

