SSH - The Preferred Login Protocol

There are several different methods, or protocols, that enable you to log into your server and gain command line access. However, only the SSH (Secure Shell) protocol should be considered secure. Secure from what, you ask? From the potential bad guys between you and your Freedom server on the Internet that could try to ""snoop"" your connection and obtain passwords or other data. We encourage all of our customers to use SSH exclusively as the protocol of choice for logging into their server. SSH provides a high level of security by encrypting the data transmitted between you and your Freedom server across the Internet.

If you connect to your Freedom server from a UNIX workstation, you more than likely already have an SSH client (and you've more than likely skipped reading this chapter as well). Users of other platforms such as Windows who wish to take advantage of the security provided by SSH will need to obtain an SSH client. The next section of this guide contains some recommended SSH client applications.

IMPORTANT NOTE:

Local and international cryptography restrictions may prevent you from using SSH or other cryptography software. Web.com is not responsible for any unauthorized use of cryptographic tools, libraries or algorithms.

For completeness, or in the event that you are unable to obtain a suitable SSH client, there are three additional methods that can be used to login to your server for command line access:

Telnet. Telnet is a popular protocol from a kinder, gentler age when security was less critical. It should only be used if you cannot use SSH because data transmitted in a Telnet session is not encrypted.  

Rlogin. Although turned off by default, your Freedom server also provides support for the use of the rlogin (remote login) protocol. Rlogin allows you to log into a Freedom account from a remote machine, similar to the way it would be done via Telnet, but with the added advantage of allowing specific users on specific machines to login without authenticating with a password. This method should not be considered secure however, because the communication is not encrypted and because the identity of remote users and servers can easily be falsified or "spoofed."

Rshell. Although turned off by default, your Freedom server also provides support for the use of the rshell (remote shell) protocol. Rshell allows you to issue command from a remote computer that you are logged into. Like rlogin, it can be configured to allow specific users on specific machines to execute commands without authenticating with a password. Also like rlogin, this method should not be considered secure because the communication is not encrypted and because the identity of remote users and servers can easily be falsified or ""spoofed.'

SSH provides secure implementations of all of the features that are available through Telnet, Rlogin and Rshell. If you can use SSH, we strongly recommend that you do so, and even recommend disabling the Telnet services altogether through the inetctl command (explained in the Network Services section of this guide) or through the Network Services tool in VAdmin.