<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <TITLE> [Mageia-dev] SSH PAM configuration </TITLE> <LINK REL="Index" HREF="index.html" > <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20SSH%20PAM%20configuration&In-Reply-To=%3C5028AE16.9050704%40gmail.com%3E"> <META NAME="robots" CONTENT="index,nofollow"> <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> <LINK REL="Previous" HREF="018088.html"> <LINK REL="Next" HREF="018096.html"> </HEAD> <BODY BGCOLOR="#ffffff"> <H1>[Mageia-dev] SSH PAM configuration</H1> <B>Guillaume Rousse</B> <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20SSH%20PAM%20configuration&In-Reply-To=%3C5028AE16.9050704%40gmail.com%3E" TITLE="[Mageia-dev] SSH PAM configuration">guillomovitch at gmail.com </A><BR> <I>Mon Aug 13 09:34:46 CEST 2012</I> <P><UL> <LI>Previous message: <A HREF="018088.html">[Mageia-dev] SSH PAM configuration </A></li> <LI>Next message: <A HREF="018096.html">[Mageia-dev] SSH PAM configuration </A></li> <LI> <B>Messages sorted by:</B> <a href="date.html#18095">[ date ]</a> <a href="thread.html#18095">[ thread ]</a> <a href="subject.html#18095">[ subject ]</a> <a href="author.html#18095">[ author ]</a> </LI> </UL> <HR> <!--beginarticle--> <PRE>Le 12/08/2012 21:57, David Walser a écrit : ><i> Johnny A. Solbu wrote: </I>>><i> On Sunday 12 August 2012 19:28, David Walser wrote: </I>>>><i> Through the PAM configuration for SSH shipped with the openssh-server package, root login is broken. Here's why. /etc/pam.d/sshd has: </I>>>><i> auth required pam_listfile.so item=user sense=deny file=/etc/ssh/denyusers </I>>>><i> </I>>>><i> The file /etc/ssh/denyusers has "root" in it by default. </I>>><i> </I>>><i> I read somewhere some time ago that PermitRootLogin in sshd_config is ignored if PAM is used. </I>>><i> That may be the reason for this. </I>><i> </I>><i> Nope, I just tested it and that is not true. </I>There is an explicit comment in the configuration file: # Depending on your PAM configuration, # PAM authentication via ChallengeResponseAuthentication may bypass # the setting of "PermitRootLogin without-password". My understanding is just than some specific PAM configuration would eventually allow root user to authenticate through a password, instead of a key. Regarding your original problem, feel free to commit the relevant modifications. -- BOFH excuse #405: Sysadmins unavailable because they are in a meeting talking about why they are unavailable so much. </PRE> <!--endarticle--> <HR> <P><UL> <!--threads--> <LI>Previous message: <A HREF="018088.html">[Mageia-dev] SSH PAM configuration </A></li> <LI>Next message: <A HREF="018096.html">[Mageia-dev] SSH PAM configuration </A></li> <LI> <B>Messages sorted by:</B> <a href="date.html#18095">[ date ]</a> <a href="thread.html#18095">[ thread ]</a> <a href="subject.html#18095">[ subject ]</a> <a href="author.html#18095">[ author ]</a> </LI> </UL> <hr> <a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev mailing list</a><br> </body></html>