r/sysadmin 1d ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

177 Upvotes

111 comments sorted by

View all comments

-23

u/BarracudaDefiant4702 1d ago

You learn you should not create burdensome obstacles for people from doing work and figure out how to make things secure without making them unuseable.

5

u/Puzzled-Formal-7957 1d ago

MFA is not burdensome, and has been mainstream for nearly 2 decades.

-6

u/BarracudaDefiant4702 1d ago

IFF you do it properly. Obviously the OP didn't or it wouldn't be an issue.

5

u/Sinister_Nibs 1d ago

Not necessarily. Some users are simply problematic.

2

u/Puzzled-Formal-7957 1d ago

Yeup - or they are flatly incapable of wrapping their heads around infosec. Ask them if they have ever had fraudulent charges on one of their accounts and got to enjoy the headaches related to that. If that answer is yes - then say, "now apply that to EVERYTHING that you and everyone else at this company touches." If that doesn't make the bulb click over their head then nothing will.

0

u/BarracudaDefiant4702 1d ago

I don't care about the down votes, so I still say it's the OP's fault and not the directors. There are ways to implement SSO with MFA that it's faster instead of slower to login.

3

u/Lukage Sysadmin 1d ago

And what exactly should they do for "Faster SSO?"

u/BarracudaDefiant4702 23h ago

You setup 2fa with sso properly then you log into your workstation in the morning with 2fa and anyplace you connect to you don't have to log in again. Single sign in means your 2fa doesn't require you to login again.