On a server I have a public key auth only for root account. Is there any point of logging in with a different account?

  • deadbeef79000@lemmy.nz
    link
    fedilink
    arrow-up
    1
    ·
    9 days ago

    That server’s root access is now vulnerable to a compromise of the systems that have the private key.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      Only the server should have the private key. Why would other systems have the private key?

      • forbiddenlake@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 days ago

        The client has the private key, the server has the corresponding public key in its authorized keys file.

        The server is vulnerable to the private key getting stolen from the client.