Skip to main content
bjazz
New Member
April 9, 2025
Question

read only user with shh rights

  • April 9, 2025
  • 3 replies
  • 1217 views

Hi, 

I am doing for backup fortigate config with oxidized tool. What I need is a read-only user to let the tool login the fw via ssh, show the config, make a diff and copy it into the git.
I created a new profile with only read rights, created a user with this profile.
When I try to ssh with this user, the ssh client directly close the connection. ¿Can you help me please? 

What am I doing wrong? 

3 replies

funkylicious
SuperUser
SuperUser
April 9, 2025

hi,

did you try assign the user in question with super_admin_readonly profile ?

also, a ssh with the admin or any other user with super_admin profile works from the server where oxidized is hosted ? maybe the IP of server needs to be added to trusted hosts.

"jack of all trades, master of none"
bjazz
bjazzAuthor
New Member
April 10, 2025

Hi, 
I tried to ssh form the oxidized server with local admin and it works fine. My read only profile is read in all options, so I think this is what you name super_admin_readonlyprofile. 

funkylicious
SuperUser
SuperUser
April 10, 2025

to be honest, I dont really know what's the difference between the built-in default admin profile, super_admin_readonly and creating a custom profile with read on all categories.

i use the built-in for backup on all devices ( used also in oxidized and netshot ) and works just fine.

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!