Authentication

VM instance with ‘Block Project-wide SSH keys’ disabled

Risk Level

Informational (4)

Platform(s)

Description

Project-wide SSH keys are stored in Compute/Project-meta-data. Project wide SSH keys can be used to login into all the instances within project. Using project-wide SSH keys eases the SSH key management but if compromised, poses the security risk which can impact all the instances within project. It is recommended to use Instance specific SSH keys which can limit the attack surface if the SSH keys are compromised.
  • Recommended Mitigation

    Enable Block project-wide SSH keys for each Vm instance