Re[2]: SSHD in JAIL

From: Igor Podlesny (poige@morning.ru)
Date: 08/04/01


Date: Sat, 4 Aug 2001 10:30:12 +0800
From: Igor Podlesny <poige@morning.ru>
To: Kris Kennaway <kris@obsecurity.org>


> On Tue, Jul 31, 2001 at 06:35:28PM -0300, Paulo Fragoso wrote:
>> On Tue, 31 Jul 2001, Kris Kennaway wrote:
>>
>> > On Tue, Jul 31, 2001 at 05:53:21PM -0300, Paulo Fragoso wrote:
>> > > Hi,
>> > >
>> > > We are making a jail using FBSD 4.3-RELEASE but in the jail sshd can't
>> > > starting:
>> > >
>> > > ssh-keygen: no RSA support in libssl and libcrypto. See ssl(8).
>> > >
>> > > How we can buildworld with RSA support in libssl or libcrypto?
>> >
>> > The error message really means "I can't find /dev/urandom" :-)
>>
>> How we can start sshd in the jail using jail directory mounted with nodev?

Let me ask what is the purpose of nodev in your situation?

I suggest using devfs (5) mounted inside your jail dir (not sure,
though, how about urandom there, but think it should be okay)... seems
it will solve the problem. At least there is a hope there ;)

> You can't: it needs /dev/urandom.
> Kris

-- 
 Igor                            mailto:poige@morning.ru
http://www.morning.ru/~poige
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re[2]: SSHD in JAIL
    ... On Sat, 4 Aug 2001, Igor Podlesny wrote: ... >>> How we can start sshd in the jail using jail directory mounted with nodev? ...
    (FreeBSD-Security)
  • [Full-disclosure] (no subject)
    ... oh so your paper rox better than all paper about chrooting sshd? ... Sometimes it may become profitable or necessary to jail the ssh daemon ... This paper will show you how to successfully jail sshd itself. ...
    (Full-Disclosure)
  • Create multiple jails by copying
    ... I created one jail in FreeBSD 4.10. ... I get an error from sendmail-client, sshd, cron, sendmail cannot ... Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org ...
    (freebsd-questions)
  • Creating multiple jails by copying
    ... I created one jail in FreeBSD 4.10. ... jail1 is functional. ... I get an error from sendmail-client, sshd, cron, sendmail cannot ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Fwd: Static Routes, gateways and the end of my sanity
    ... -}The scenario is that I have a server here with twin nics, bce0 and bce1; ... sshd is running inside the jail;). ... parent's sshd_config needs to say "ListenAddress 10.228.228.228". ...
    (freebsd-questions)