Re: [Q] openssh-3.8.1p1 + radius PAM

From: Logu (logsnaath_at_gmx.net)
Date: 08/18/04

  • Next message: Daniel Miessler: "Re: Login Problem using SSh in Solaris"
    To: <secureshell@securityfocus.com>
    Date: Wed, 18 Aug 2004 11:13:12 +0530
    
    

    > I have a linux box being used as a firewall router and wanted to use ssh
    > with radius authentication (same radius used to authenticate for other
    > networking equipment). I modified the radius PAM to replace a valid
    > radius user with a generic username (I don't really want a lot of user
    > accounts on the box, but want to keep track of who logged on via radius
    > log).
    >
    > With telnet the configuration works (goal is to turn off telnet), but with
    > ssh it appears to authenticate the user inside SSH first (basically
    > ignoring the settings in /etc/pam.d/sshd). Is there any trick to having
    > SSH authenticate first to the radius PAM (so it can replace the username
    > with the generic one)?

    Have you enabled pam while compiling? If yes, have you set "UsePam Yes" in
    the sshd_config file.

    -Logu


  • Next message: Daniel Miessler: "Re: Login Problem using SSh in Solaris"

    Relevant Pages

    • Re: 802.1x authentication for wireless issues w/ ISA 2004
      ... The do support WPA-EAP and the radius ... authenticate the computer and this is trying to authenticate the user and not ... If you can post perhaps 10 lines from the IAS log, ... represent my IAS server or the client laptops. ...
      (microsoft.public.windows.server.sbs)
    • [Q] openssh-3.8.1p1 + radius PAM
      ... I have a linux box being used as a firewall router and wanted to use ssh ... with radius authentication (same radius used to authenticate for other ... SSH authenticate first to the radius PAM (so it can replace the username ...
      (SSH)
    • Re: IAS/RADIUS question - solved (almost)
      ... pair of 2-way external trusts on each domain. ... RADIUS server on domain TWO. ... When a user of one.foo.com attempts to authenticate ...
      (microsoft.public.internet.radius)
    • Re: authenticate proxy requests with AD computer accounts
      ... It's just to authenticate my internal users. ... so we want to oblige them by blocking them internet access. ... What do you mean with radius is used between NAS & proxy? ...
      (microsoft.public.internet.radius)
    • IIS/ASP authentication with RADIUS
      ... Does anyone know if there is a way to let IIS users ... RADIUS is running on one of the Novell servers one of my ... server to authenticate against this client's ...
      (microsoft.public.inetserver.iis.security)