diff options
Diffstat (limited to 'zarb-ml/mageia-dev/2012-August/018101.html')
-rw-r--r-- | zarb-ml/mageia-dev/2012-August/018101.html | 149 |
1 files changed, 149 insertions, 0 deletions
diff --git a/zarb-ml/mageia-dev/2012-August/018101.html b/zarb-ml/mageia-dev/2012-August/018101.html new file mode 100644 index 000000000..adc8e2958 --- /dev/null +++ b/zarb-ml/mageia-dev/2012-August/018101.html @@ -0,0 +1,149 @@ +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> +<HTML> + <HEAD> + <TITLE> [Mageia-dev] SSH PAM configuration + </TITLE> + <LINK REL="Index" HREF="index.html" > + <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20SSH%20PAM%20configuration&In-Reply-To=%3C5028D073.2010105%40kde.org%3E"> + <META NAME="robots" CONTENT="index,nofollow"> + <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> + <LINK REL="Previous" HREF="018100.html"> + <LINK REL="Next" HREF="018102.html"> + </HEAD> + <BODY BGCOLOR="#ffffff"> + <H1>[Mageia-dev] SSH PAM configuration</H1> + <B>Anne Wilson</B> + <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20SSH%20PAM%20configuration&In-Reply-To=%3C5028D073.2010105%40kde.org%3E" + TITLE="[Mageia-dev] SSH PAM configuration">annew at kde.org + </A><BR> + <I>Mon Aug 13 12:01:23 CEST 2012</I> + <P><UL> + <LI>Previous message: <A HREF="018100.html">[Mageia-dev] SSH PAM configuration +</A></li> + <LI>Next message: <A HREF="018102.html">[Mageia-dev] SSH PAM configuration +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#18101">[ date ]</a> + <a href="thread.html#18101">[ thread ]</a> + <a href="subject.html#18101">[ subject ]</a> + <a href="author.html#18101">[ author ]</a> + </LI> + </UL> + <HR> +<!--beginarticle--> +<PRE>-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA1 + +On 13/08/12 09:58, Pascal Terjan wrote: +><i> On Mon, Aug 13, 2012 at 9:39 AM, Anne Wilson <<A HREF="https://www.mageia.org/mailman/listinfo/mageia-dev">annew at kde.org</A>> +</I>><i> wrote: +</I>>><i> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 +</I>>><i> +</I>>><i> On 13/08/12 08:34, Guillaume Rousse wrote: +</I>>>><i> Le 12/08/2012 21:57, David Walser a écrit : +</I>>>>><i> Johnny A. Solbu wrote: +</I>>>>>><i> On Sunday 12 August 2012 19:28, David Walser wrote: +</I>>>>>>><i> Through the PAM configuration for SSH shipped with the +</I>>>>>>><i> openssh-server package, root login is broken. Here's +</I>>>>>>><i> why. /etc/pam.d/sshd has: auth required pam_listfile.so +</I>>>>>>><i> item=user sense=deny file=/etc/ssh/denyusers +</I>>>>>>><i> +</I>>>>>>><i> The file /etc/ssh/denyusers has "root" in it by default. +</I>>>>>><i> +</I>>>>>><i> I read somewhere some time ago that PermitRootLogin in +</I>>>>>><i> sshd_config is ignored if PAM is used. That may be the +</I>>>>>><i> reason for this. +</I>>>>><i> +</I>>>>><i> Nope, I just tested it and that is not true. +</I>>>><i> There is an explicit comment in the configuration file: # +</I>>>><i> Depending on your PAM configuration, # PAM authentication via +</I>>>><i> ChallengeResponseAuthentication may bypass # the setting of +</I>>>><i> "PermitRootLogin without-password". +</I>>>><i> +</I>>>><i> My understanding is just than some specific PAM configuration +</I>>>><i> would eventually allow root user to authenticate through a +</I>>>><i> password, instead of a key. +</I>>>><i> +</I>>>><i> Regarding your original problem, feel free to commit the +</I>>>><i> relevant modifications. +</I>>><i> +</I>>><i> Why would anyone need root login over ssh? I don't allow it on +</I>>><i> my server and it has never caused me any problems. Su to root +</I>>><i> works perfectly well and avoids the security risk, so I don't +</I>>><i> understand this thread. +</I>><i> +</I>><i> Allowing login as root over ssh with a key can save things when +</I>><i> for some reason non local auth is down, like to fix the connection +</I>><i> to the ldap server (you can also create a local emergency account +</I>><i> for that usage). +</I> +OK, thanks for the answer. Looks like some more reading on this +subject is required :-) Although I do use login over ssh with keys +(as user) I don't use ldap, so I've never come across this. + +Anne + +- -- +Need KDE help? Try +<A HREF="http://userbase.kde.org">http://userbase.kde.org</A> or +<A HREF="http://forum.kde.org">http://forum.kde.org</A> +-----BEGIN PGP SIGNATURE----- +Version: GnuPG v1.4.12 (GNU/Linux) +Comment: Using GnuPG with Mozilla - <A HREF="http://enigmail.mozdev.org/">http://enigmail.mozdev.org/</A> + +iEYEARECAAYFAlAo0GsACgkQj93fyh4cnBfqXACePg37FlvBQ8xkei9+GNXivQdo +IA4AoIppYO9aPb2YGG8aXA16fy86RxNg +=Om7Z +-----END PGP SIGNATURE----- +</PRE> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +<!--endarticle--> + <HR> + <P><UL> + <!--threads--> + <LI>Previous message: <A HREF="018100.html">[Mageia-dev] SSH PAM configuration +</A></li> + <LI>Next message: <A HREF="018102.html">[Mageia-dev] SSH PAM configuration +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#18101">[ date ]</a> + <a href="thread.html#18101">[ thread ]</a> + <a href="subject.html#18101">[ subject ]</a> + <a href="author.html#18101">[ author ]</a> + </LI> + </UL> + +<hr> +<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev +mailing list</a><br> +</body></html> |