Re: pam_skey configuration

From: Binesh Bannerjee (binesh-dated-1089107621.544069_at_hex21.com)
Date: 06/29/04

  • Next message: Larry Gagnon: "do I need to run saslauthd?"
    Date: 29 Jun 2004 09:59:55 GMT
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Binesh Bannerjee <binesh-dated-1089106274.dd2d54@hex21.com> wrote:

    > auth sufficient /lib/security/pam_skey.so
    > auth required /lib/security/pam_skey_access.so
    > auth required /lib/security/pam_nologin.so
    > account required /lib/security/pam_unix.so
    > password required /lib/security/pam_unix.so shadow use_authtok
    > session required /lib/security/pam_unix.so

    OK, well, replacing pam_nologin with pam_deny seeme to have made it
    work. Meaning, it now will let me login via public key authentication or
    s/key authentication, but, not via passwords, as opposed to before, when
    it allowed, public key authentication, s/key authentication or it _simply_
    allowed you through right password, or no!!! (eeep!) How silly of me. In
    any case, tho I'm still wondering if that's the best way of doing it or
    not... Any suggestions would be appreciated.

    Thanks again!
    Binesh Bannerjee

    - - --
    'One of the cultural barriers that separates computer scientists from
     "regular" scientists and engineers is ... the practical scientist is
     trying to solve tomorrow's problem with yesterday's computer; the
     computer scientist, we think, often has it the other way around.'
            -- Numerical Recipes in C

        PGP Key: http://www.hex21.com/~binesh/binesh-public.asc
    PGP Key fingerprint = 421D B4C2 2E96 B8EE 7190 A0CF B42F E71C 7FC3 AD96

        SSH2 Key: http://www.hex21.com/~binesh/binesh-ssh2.pub
    OpenSSH Key: http://www.hex21.com/~binesh/binesh-openssh.pub
    BubbleBabble = xibeb-voges-havez-pabaf-debop-cylil-lelyc-viruv-bygeg-zotoh-dixex
     Fingerprint = 9d:7c:84:5d:80:e3:65:8d:ee:9e:a3:b9:56:0a:e9:ad

        SSH1 Key: http://www.hex21.com/~binesh/binesh-ssh1.pub

    CipherKnight Seals:
            http://www.hex21.com/~binesh/binesh-seal.tar.bz2.cs256
            http://www.hex21.com/~binesh/binesh-seal.zip.cs256
            http://www.hex21.com/~binesh/binesh-certificate.gif.cs256
            Decrypt with CipherSaber2 N=256, Password="WelcomeJedi!" (No quotes)
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (GNU/Linux)

    iD8DBQFA4T2NtC/nHH/DrZYRAjIPAJwLKwvcUUUlYvui7ybI894QULPwLACg6J8+
    6jDAEvP9bSOOANa0+KmvK/0=
    =p4CN
    -----END PGP SIGNATURE-----


  • Next message: Larry Gagnon: "do I need to run saslauthd?"

    Relevant Pages

    • Re: Backspace At Login Puzzle
      ... > Configure public key authentication or use passwords. ... OMT, there is a bundled ssh server with Solaris 9. ...
      (comp.unix.solaris)
    • Re: Hacked mac
      ... Tom Stiller wrote: ... Tom, i've seen you advocate public key authentication quite a bit, so ... instead of passwords, how do you fully disable password authentication? ... You shouldn't need to do this, as sshd is managed by xinetd and is only ...
      (comp.sys.mac.system)
    • Re: Hacked mac
      ... Tom Stiller wrote: ... Tom, i've seen you advocate public key authentication quite a bit, so ... instead of passwords, how do you fully disable password authentication? ... You shouldn't need to do this, as sshd is managed by xinetd and is only ...
      (comp.sys.mac.system)
    • Re: SSH hacked?
      ... Why use passwords at all with SSH? ... public key authentication is several orders of magnitude harder to crack ...
      (Ubuntu)
    • Re: Stopping Brute Force SSH Attacks
      ... ]>~/.ssh/authorized_keys2 files (and those keys have passwords). ... ]I only use public key authentication. ... ]where I try to login before adding my key to ssh-agent, ...
      (comp.security.ssh)