> /etc/security/access is definitely an option, as would be putting them > all in a group and using "AllowGroups [your group]" in the sshd_config, > among other possibilities. > > Doing something group-based is typically pretty easy to manage. Thanks for the info, the sshd_config file may be the way to go. We already use cfengine so it would be fairly easy to implement and push out to all our servers.