Re: PAM SecurID from RSA

From: Julian Elischer (julian_at_vicor.com)
Date: 10/07/03

  • Next message: Darren Tucker: "Re: SSH 3.2.5 Secure Shell and AIX 5L ver. 5.1"
    Date: Tue, 07 Oct 2003 14:31:01 -0700
    To: Asif Iqbal <iqbala@qwestip.net>
    
    

    We just run pam_radius and use the RSA alterred radiusd to do the SecureID
    work..

    Asif Iqbal wrote:
    > Has anyone tried to use PAM SecurID from RSA ?
    >
    > I compiled openssh-3.7.1p2 this way
    >
    > ./configure --disable-suid-ssh --with-privsep-user=sshd
    > --with-privsep-path=/var/empty --without-prngd --without-rand-helper
    > --with-ssl-dir=/usr/local/ssl --with-tcp-wrappers --with-pam
    >
    > And then use these two entries in sshd_config as recommened by RSA
    >
    > PAMAuthenticationViaKbdInt yes
    > UsePrivilegeSeparation no
    >
    > Its not working for SecurID. This is what it says
    >
    > debug1: userauth-request for user iqbala service ssh-connection method none
    > debug1: attempt 0 failures 0
    > debug2: input_userauth_request: setting up authctxt for iqbala
    > debug2: input_userauth_request: try method none
    > Failed none for iqbala from 1.2.3.4 port 3067 ssh2
    > debug1: userauth-request for user iqbala service ssh-connection method
    > keyboard-interactive
    > debug1: attempt 1 failures 1
    > debug2: input_userauth_request: try method keyboard-interactive
    > debug1: keyboard-interactive devs
    > debug1: auth2_challenge: user=iqbala devs=
    > debug1: kbdint_alloc: devices 'pam'
    > debug2: auth2_challenge_start: devices pam
    > debug2: kbdint_next_device: devices <empty>
    > debug1: auth2_challenge_start: trying authentication method 'pam'
    > Failed keyboard-interactive for iqbala from 1.2.3.4 port 3067 ssh2
    >
    > Please let me know if anyone made it work. Also I don't like the idea that they
    > recommeded not to use PrivSep. Whats anyone's thought on this ?
    >
    > Thanks


  • Next message: Darren Tucker: "Re: SSH 3.2.5 Secure Shell and AIX 5L ver. 5.1"

    Relevant Pages

    • Re: Was ist los mit RSA?
      ... Was ist hier in der Tat los mit RSA? ... Das du da draus nicht viel Konkretes entnehmen kannst, ... den SecureID kram. ...
      (de.comp.security.misc)
    • Re: Break in at RSA
      ... Any breach of the system means that it will be easier for attackers to get into any systems that use SecureID for authentication. ... the firm RSA, would it be feasible for a bad worker of the firm RSA to ... This breach may been that attackers can create counterfeit cards, but they still have the problem of the users' passwords to deal with. ...
      (sci.crypt)
    • Re: Was ist los mit RSA?
      ... Was ist hier in der Tat los mit RSA?> ... RSA Inc. gegruendet haben. ... naemlich diese SecureID Tokens. ... L?cke in der Implementierung hinterlassen hat oder, ...
      (de.comp.security.misc)
    • Re: EBAY Konten-Computer-Bindung
      ... der Regel ein PRNG mit einem eindeutigen Seed und Timer. ... (RSA) ... SecureID ...
      (de.comp.security.misc)