Authentication is not enough; a human approval is required.
RaWarden gates every privileged SSH session behind a human approval decision. The operator authenticates, sees a one-time code in their terminal, and no root shell opens until the panel says so.
$ ssh root@server
OTURUM ONAY KODU: 482-917
Panel'de onaylayın — 60s zaman aşımı
[panel onayı bekleniyor...]
✓ Onaylandı → privilege drop → shell
Wired into OpenSSH as a ForceCommand. Even after the operator authenticates with a valid key, the session is frozen until an authorized admin approves it in the panel. Authentication is no longer sufficient.
The approving admin assigns the target user and UID at decision time. RaWarden performs the full setgroups/setgid/setuid transition so the audit trail shows root → real user, not just 'root logged in'.
Correctly sets SELinux execution contexts, writes the true loginuid for auditd, and re-chowns the SSH agent socket to the target user. Works on STIG/CIS-hardened hosts without fighting the security policy.
If the control plane is unreachable, the session is denied — not blindly allowed. Every gate event — initiated, approved, denied, timed out — is written to local LOG_AUTH.
Integrate RaTurka into your production environment in minutes. Deploy the agent with a single command and put operational chaos behind you.
Free plan available — no credit card required.