SSH/SSL Admin Settings5 minutes to read
PAM360 allows you to enable notifications for various operations such as SSL key expiry, failed SSH key rotation, certificate management, PGP key expiry, etc. In addition, PAM360 allows you to retain or overwrite existing keys. Here in this document you will learn about the following topics: 1. Managing NotificationsYou can set up to get notified via email, syslog messages in any of the following cases:
Note: Notifications regarding PGP key expiration will be sent via email only. To configure notifications:
![]() ![]() Note: Expiring SSL certificates, and the SSH keys that were not rotated within the specified days are notified during the mentioned Recurrence Time. ![]() Note : The number of days specified in the SSH key rotation and SSL certificate expiry notification policy will be applied to the dashboard settings also. 2. SSH Policy ConfigurationPAM360 allows you to create a high level policy on SSH keys management. when PAM360 creates new keys, you can specify whether to retain (ie. to be appended to the existing ones) or overwrite the existing keys. Overwriting will remove the existing keys and allows you to have a fresh start. Your SSH environment will have only the keys that were generated by the PAM360. PAM360 carries out these changes in the authorized_keys file directly. From the SSH Policy, you can set the option for adding keys to the authorized_keys file. You can choose from:
To change the policy configuration:
![]() You will get a confirmation that the SSH policy settings have been updated. | |