Remove ability for gvm
user to obtain shell and restrict the port-forwards possible
#181
Labels
gvm
user to obtain shell and restrict the port-forwards possible
#181
Is your feature request related to a problem? Please describe.
Currently it appears
sshd_config
is restricted to thegvm
user with nicely appropriate authentication and encryption settings.However, this
sshd_config
does not prevent thegvm
user from being able to establish a shell or creating arbitrary port-forwards.In the undesirable situation where the associated SSH private-key ends up in the wrong hands it would be better if the
gvm
user had less freedoms and was more limited in what it can achieve beyond the ssh-port-forward requirement.Describe the solution you'd like
Add restrictions to
sshd_config
and thegvm
user by introducing configuration items as suggested below - I do not have a test/development environment available to confirm the config below can be cut-n-paste into place - presented here as a guide and outline the intent.Describe alternatives you've considered
None
Additional context
None
The text was updated successfully, but these errors were encountered: