SSH question

From: Armin M. Safarians (armin.safarians_at_safeway.com)
Date: 07/16/03

  • Next message: Peter Mueller: "RE: Problem after SSH/SSL upgrade"
    Date: Wed, 16 Jul 2003 08:59:10 -0700
    To: secureshell@securityfocus.com
    
    

      I hope someone can help with this finding.
    We are investigating centralized control of the authorized_keys file in
    a root owned directory with world readable permission so we can control
    key usage. we have added user1@hosta's key into this file.

    Here is the situation:

    user1@hosta has a key on hostb in the authorized_keys file.

    from hosta, user1 can ssh user2@hostb and login using user1's key
    (doesn't matter if a passphrase is set or not, if an agent is running or
    not)

    It seems that so long as user1 has a key on any machine, and it exists
    in the authorized_keys file, user1 can ssh to those remote hosts as
    anyone else.

    It seems that the commercial version has solve this by not adding the
    key itself in the authorized_keys file, rather a directive "Key
    user1key.pub" and then controlling the read on the key file to only user1.

    AMS :-)

    -- 
    Armin M. Safarians	Safeway Inc. 
    VOICE: 925.944.4246 
    EMAIL:armin.safarians@Safeway.com
    ****************************************************************
    Success is the result of preparation, hard work, and learning
    from mistakes.
    ****************************************************************
    "MMS <safeway.com>" made the following annotations.
    ------------------------------------------------------------------------------
    Warning: 
    All e-mail sent to this address will be received by the Safeway corporate
    e-mail system, and is subject to archival and review by someone other than the
    recipient.  This e-mail may contain information proprietary to Safeway and is
    intended only for the use of the intended recipient(s).  If the reader of this
    message is not the intended recipient(s), you are notified that you have
    received this message in error and that any review, dissemination,
    distribution or copying of this message is strictly prohibited.  If you have
    received this message in error, please notify the sender immediately. 
      
    ==============================================================================
    

  • Next message: Peter Mueller: "RE: Problem after SSH/SSL upgrade"

    Relevant Pages

    • Send As for DL not working
      ... I've given user1 Full Control over the ... I can't give Send On Behalf Of permission, because jobs ... tab does not have that control. ...
      (microsoft.public.exchange2000.admin)
    • Re: 2000 to 2003 Migration - ADMT V.2
      ... Please add the user1 to the share permission list and set Full Control. ... Get Secure! ... When responding to posts, please "Reply to Group" via your newsreader so ...
      (microsoft.public.windows.server.migration)
    • Re: Narrowing It Down
      ... and Canon and assuming you can get equivalent image quality on both ... function has a dedicated button well placed on the Nikon camera it ... The only specific criticism I could find in the review that used the word "horrible" was "I find it difficult to simultaneously cover the control dial, the shutter release, and the back-panel wheel with my fingers and thumb – and next to impossible while shooting one-handed." ... I realize that I may be in the minority when I say this, but while I find the 50D's body to feel fantastic, the general control layout is horrible. ...
      (rec.photo.digital)
    • Re: How do I permanently shut-off the Reviewing Toolbar?
      ... it is not possible for you to control the 'view' of an incomplete document on everyone else's computer. ... The 'Original' choice shows how the document 'would be if' you rejected all of the pending tracked changes then saved the document. ... I understand how to accept all comments, turn off the review feature, etc. - ... MS Office System Products MVP ...
      (microsoft.public.word.docmanagement)
    • Re: How to find a "diff" visually?
      ... >> clean source. ... I may not always have automated version control but I ... > w/o review, before the weekly build, back in the Silicon Valley ... software on a table on a mechanical drawing set of the embedded ...
      (comp.arch.embedded)