To overcome this issue, you end up storing a set of public keys in the servers themselves, thereby going back to where you started.
To overcome this issue, you end up storing a set of public keys in the servers themselves, thereby going back to where you started.
https://access.redhat.com/documentation/en-us/red_hat_enterp...
Our systems people get local accounts on machines for disasters like LDAP-down. Everyone else is LDAP-only, including ssh keys.
This is nowhere close to "where we started". Now we have a handful of privileged accounts and centralized auth management across thousands of other accounts.
Centralized logging and centralized auth are pretty much mandatory above some size. Without them, you literally do not know who is doing what.
That way you get both emergency access in case LDAP is broken, as well as a way to make sure old personal access gets revoked after one month.
There are of course also DR considerations for that, as always, it is turtles all the way down.