Skip to main content
ede_pfau
SuperUser
SuperUser
March 2, 2019
Question

Admin auth per SSH key and LDAP

  • March 2, 2019
  • 1 reply
  • 10314 views

Hello fellows,

 

for simplicity, I often use my private SSH key to log in into my local admin account on various FGTs (I mean, CLI access via SSH). Now, if instead of a local admin account I use a wildcard admin account against LDAP/MS AD in the background, I cannot use this anymore.

Any ideas how to work around this?

 

    1 reply

    xsilver_FTNT
    Staff
    Staff
    March 4, 2019

    Hi Ede,

    how do you expect it to work ? Like one public key for everyone eligible to login through LDAP ?

     

    In this type of remote users is password, and so I believe key as well, used as fallback option if remote server is not reachable or do not respond to authentication attempts.

     

    Workaround might be in the way that remote server will read and use provided password as key.

    ede_pfau
    SuperUser
    ede_pfauAuthor
    SuperUser
    March 4, 2019

    You're right, "how do you expect it to work?" Seems you can't have the pudding and eat it.

    xsilver_FTNT
    Staff
    Staff
    March 4, 2019

    yes.

    Seems to me that all the modern tech is about the same ... options are "cheap", "fast" and "reliable/robust", and you can choose two but newer be able to get all three in one product.