RE: restricting originating IP per user

From: Kim, Anthony (anthony.kim@vw.com)
Date: 12/13/02

  • Next message: Attica: "Re: restricting originating IP per user"
    From: "Kim, Anthony" <anthony.kim@vw.com>
    To: 'Attica' <attica@stackheap.org>
    Date: Fri, 13 Dec 2002 09:14:54 -0600
    
    

    From sshd_config(5)

    PermitRootLogin
     Specifies whether root can login using ssh(1). The argument must
     be ``yes'', ``without-password'', ``forced-commands-only'' or
     ``no''. The default is ``yes''.

     If this option is set to ``without-password'' password authenti­
     cation is disabled for root.

     If this option is set to ``forced-commands-only'' root login with
     public key authentication will be allowed, but only if the
     command option has been specified (which may be useful for taking
     remote backups even if root login is normally not allowed). All
     other authentication methods are disabled for root.

     If this option is set to ``no'' root is not allowed to login.

    HTH,
    Anthony

    -----Original Message-----
    From: Attica [mailto:attica@stackheap.org]
    Sent: Thursday, December 12, 2002 3:04 PM
    To: Kim, Anthony
    Cc: secureshell@securityfocus.com
    Subject: RE: restricting originating IP per user

    On Wed, 4 Dec 2002, Kim, Anthony wrote:

    > Actually, this works for me (OpenSSH-3.4p1)
    > from="10.10.100.5,192.168.*,127.*" ssh-rsa AAAA[rest of key]

    This is very cool and I'm now using this. However, while this does
    restrict which key a user can use for password-less authentication, the
    password itself can be brute forced right?

    For example, let's say I need to have a particular IP scp as root for a
    nightly backup (BackupPC to be specific). It can't have a passphrase,
    which is fine, but I do need to make "PermitRootLogin yes" in my
    sshd_config file. Now can't people try to brute force root's password?

    I'm betting there's a way to specify that root cannot log in via password
    (i.e. only public-key) without affecting mere mortal accounts, but I don't
    know how to do it offhand...

    Attica
    ***********************************************************************
    DISCLAIMER: The information transmitted may contain confidential material
    and is intended only for the person or entity to which it is addressed. Any
    review, retransmission, dissemination or other use of or taking of any
    action by persons or entities other than the intended recipient is
    prohibited. If you are not the intended recipient, please delete the
    information from your system and contact the sender.
    ***********************************************************************



    Relevant Pages

    • SUMARY: Cant login as root
      ... As a result, i was not able to log in as root, neither create a new ... Asunto: RE: Can't login as root ... > console. ... > If we log as any other user everythig is ok, but we cannot either do su-. ...
      (Tru64-UNIX-Managers)
    • RE: Urgent help needed with Login problems after installation of FC1
      ... symptom trying to su back to root. ... After another minimal install, I was able to add my user and su to it and su ... I was unable to boot using the boot floppy. ... I did a minimal install and was able to login as root, ...
      (Fedora)
    • Re: BSM, SSH, and Session ID
      ... Are you logging in as root through ssh or is that just the way it is ... Sun SSH/OpenSSH should fork off before the login because the sshd ... It should always be a different session, ...
      (Focus-SUN)
    • Re: Urgent help needed with Login problems after installation of FC1
      ... login would do anything but loop back to the Login: ... >From Gnome desktop, I was able to logout user, login root, over and ... Am able to boot from floppy. ... >After another minimal install, I was able to add my user and su to ...
      (Fedora)
    • Re: i can not log as a root
      ... >> how i can log as a user but not as a root. ... > Problem seems to be with the X session not your login but we'll try a few ... > select the OS/kernel that you boot to, ... > Looks like something is wrong with your Xsessions script or one of the ...
      (linux.redhat)