Restrict sftp access to sftp only, specific IP only, within chroot jail, and monitor with full logging
The problem
A certain web application requires sftp access to a storage server to use it as external storage. This means that the login credentials (password or private key) will have to be stored on application server, which poses a secrutiy risk for the storage server. If the application server …
more ...