That’s what I do currently with some of my hosts.
That’s what I do currently with some of my hosts.
SSH can sometimes authenticate intent, like Yubikey touch.
Using wireguard for authentication is a mistake. The category of mistake is usually referred to as ambient authority, often exploited via a confused deputy.
In one sense, this is no different than adding a public key to ~/ssh/authorized_keys.
If you control the key, you control the authentication.
> I heard that ssh is kinda of an unnecessary step
What makes SSH different is the encrypting part. The keys were only introduced to be used by the encryption algorithms. Users and multiple identities were a core detail of nixes much before SSH
I said that even rsh would do because will can ignore all the weird outdated stuff and just login with an user and password, same as a local login. In that case telnet would also work.
However, I truly believe that cryptographic keys are way superior to passwords. And going back to them would be a huge step back
.. but that doesn't gain all that much tbh.if anything the only hesitation I'd have on listening to * and relying on firewall rules is if the service comes up before its configured. but exposing sshd isn't even that bad
https://www.freedesktop.org/software/systemd/man/latest/syst...