Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

creates ssh host key on build #13

Open
kiney opened this issue Feb 6, 2018 · 3 comments
Open

creates ssh host key on build #13

kiney opened this issue Feb 6, 2018 · 3 comments

Comments

@kiney
Copy link

kiney commented Feb 6, 2018

The ssh host key is created generated in the apt/deb script. So in case of this image at build time.
Using prebuilt images (from dockerhub) therefore is a security risk.

@rastasheep
Copy link
Owner

Hi @kiney thanks for note!

Do you think if generating key in runtime will make difference since root login is enabled and dummy password is used?

@rastasheep
Copy link
Owner

We've added security notice to the readme (#20), also there are now commands for how to improve it. Do you suggest anything else to add?

@kiney
Copy link
Author

kiney commented Aug 14, 2018

Hi, thanks for the answer.
Problem with re-using host keys that are present in public builds is that there's no way to protect against MITM attacks. For some use cases this is no problem, for others it is.
It should just be clear from documentation. I personally just run my own builds to have my own host keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants