Re: OpenSSH b0rked (was RE: Problems with IPFW patch)

From: Rasputin (rasputin@FreeBSD-uk.eu.org)
Date: 01/29/01


Date: Mon, 29 Jan 2001 09:57:53 +0000
From: Rasputin <rasputin@FreeBSD-uk.eu.org>
To: freebsd-security@freebsd.org


* Matt Dillon <dillon@earth.backplane.com> [010126 21:55]:
> :I would ask, that in -STABLE at least, the fatal error be backed
> :out to a warning, at least for a few months (with sshd ignoring the
> :directive, and continuing to run), and then only move to a fatal
> :error + die.
> :
> :-aDe
>
> I second this request. It also happened when pam.conf/ssh changed.
> Only the serial console saved me from a car trip to one of my
> colocated machines. Two such changes in a row for ssh is too much.
>
> -Matt

In general I'd agree with Matt and aDe, but if a directive
affecting security has changed, I'd say it's better to be notified of it
as soon as possible.
Killing off sshd obviously makes remote admin a real problem, though;
is there another way to guarantee we'd notice ?
 

-- 
Rasputin 
Jack of All Trades :: Master of Nuns
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: OpenSSH b0rked (was RE: Problems with IPFW patch)
    ... >:I would ask, that in -STABLE at least, the fatal error be backed ... >:out to a warning, at least for a few months (with sshd ignoring the ... > colocated machines. ... sshd now uses PAM by default. ...
    (FreeBSD-Security)
  • Re: RFC: mistaken regexps: should they be fatal?
    ... I added a warning to the development gawk as follows: ... about whether this kind of thing should be a fatal error; ... A fatal error seems to me to be a harsh awk reaction in this case. ...
    (comp.lang.awk)
  • Re: how to organize my main file ?
    ... This is to print a warning - the line where it occured, ... Generally failure to obtain critical resources ... insufficient to terminate the program. ... the program intact can be just a "warning" while a fatal error is one ...
    (comp.lang.c)
  • Re: Unrecognized escape sequences in string literals
    ... Isn't that a warning, not a fatal error? ... Should I assume that Microsoft's C++ compiler treats it as an error, ... a s rin\g with escapes ...
    (comp.lang.python)
  • Sendmail 8.12 SCO OS5.0.7
    ... line 2615: warning: type does not match prototype: pid ... *** Error code 1 (bu21) ... UX:make: ERROR: fatal error. ...
    (comp.unix.sco.misc)