AIX, rsh, rlogin = false, openssh

From: Gael Martinez (gael@magicnet.org)
Date: 12/12/02

  • Next message: Noah Salzman: "Re: Passwordless ssh, "once and for all"..."
    Date: Thu, 12 Dec 2002 12:41:01 -0600
    From: Gael Martinez <gael@magicnet.org>
    To: secureshell@securityfocus.com
    
    

    On Aix 4.3.3, when setuping some user to rlogin = false in
    /etc/security/users, he still can use rsh to execute remote commands but
    not to log the server, I m trying to reach the same point with
    openssh but openssh directly reject the connections with a user unknown...

    example:

    host1$ rsh remote ls
    file
    file2

    host1$ ssh remote ls
    user@remote passwd:

    how can I get openssh to accept remote scp/sftp with keys but reject any
    other kind of login when keeping the rlogin = false in the user
    profile ?

    Of course when turning on rlogin, it works fine, but as other services are
    still enabled, I cannot live with it...

    Regards

    Gael



    Relevant Pages

    • AIX, rsh, rlogin = false, openssh
      ... openssh but openssh directly reject the connections with a user unknown... ... host1$ rsh remote ls ... other kind of login when keeping the rlogin = false in the user ...
      (comp.security.ssh)
    • AIX421 root password lost
      ... I deleted that post about the lost remote root password, ... This a problem with the way login parses it arguments as passed by rlogind ... command line option -fUSER as -f USER. ...
      (AIX-L)
    • Re: redirect to tty
      ... >>the rlogin terminal, but the ls command is not executed on ... >>the remote host I rlogined, do I have a way I can achieve this ... > To remote execute a command, ...
      (comp.unix.programmer)
    • ftp sftp, sh ssh, cp scp, ..., rpc srpc?
      ... Any binary prefixed with r (such as rcp, rlogin, rexec, or rcmd) will ... SANS.ORG pointed out that Remote Procedure Calls are one of ...
      (comp.security.ssh)
    • [CLA-2002:500] Conectiva Linux Security Announcement - openssh
      ... SUMMARY: Remote vulnerability in OpenSSH ... It is recommended that all OpenSSH users upgrade their packages. ...
      (Bugtraq)