Separately, I don't know what other - if any - features a db-backed ssh server needs to provide. Is this all that is necessary?
Separately, I don't know what other - if any - features a db-backed ssh server needs to provide. Is this all that is necessary?
In our case, the SSH server is not for general purpose, but for something really specific, so it's really easier to test. What other feature? As I will explain next week, our SSH server is actually an authentication/autorization proxy which forwards connections to another server. By building our solution, it is now easier to control the logics for the load balancing etc.
On the other hand, OpenSSH's server has become so big that even when it is perfectly implementing the security contract its authors intend it can still allow users to do things that may surprise the heck out of you. Given what I've seen of trying to secure things that use SSH and really shouldn't, I would believe it might be easier to audit your own server rather than a deployment of opensshd.