Thanks for the links, Teleport seems especially interesting.
Yeah, we are required by contractual obligations to log these things or at least sudo commands. Don't disagree that it's less than useful but only so many things you can argue about. The logging we can do with auditd but we need unique instance users for that to be useful.
Comments
Thanks for the links, Teleport seems especially interesting.
Yeah, we are required by contractual obligations to log these things or at least sudo commands. Don't disagree that it's less than useful but only so many things you can argue about. The logging we can do with auditd but we need unique instance users for that to be useful.
(disclaimer, I was a founder of ScaleFT - acquired by Okta)
This is exactly why many customers use Okta's Advanced Server Access: https://www.okta.com/products/advanced-server-access/
It does certificates as a credentialing mechanism, but also full separate accounts, lifecycle management of accounts and sudo files.