Re: Bug or feature?

From: Richard E. Silverman (slade@shore.net)
Date: 03/16/02


From: slade@shore.net (Richard E. Silverman)
Date: 16 Mar 2002 01:05:57 -0500


>>>>> "MS" == Martin Schroeder <emes@geomer.de> writes:

    MS> Hi, just a simple question.

    MS> If you set the AuthorizedKeysFile to an absolute path (ie.
    MS> AuthorizedKeysFile /var/ssh/authorized_keys2) in sshd_config, then
    MS> any user who's key is listed in authorized_keys2 can become any
    MS> user on the system (including root). Is this a bug or feature?

I'm not sure whether you're asking if this behavior is due to a
programming error, or if it's just not a good idea. It's not a bug in
that it corresponds to the documented behavior.

By giving an absolute pathname that does not include any variables (%h
etc.), you have given every account the same public-key authorization
file. So of course, any key listed there can access any account.

-- 
  Richard Silverman
  slade@shore.net



Relevant Pages

  • Re: BUG or FEATURE
    ... needs to prove that "See this seems to be a bug to me - I am typical ... and no where it is mentioned that the feature should work like this". ... lack of knowledge that "there is no Oracle". ... which ones (does management think) are the most ...
    (comp.software.testing)
  • Re: BUG or FEATURE
    ... 10x two all for replay. ... work better/easier will be a feature and not bug. ... goes to oracle. ...
    (comp.software.testing)
  • Re: Looking for the antonym for enhancement - A SolidWords study.
    ... from dictionaries and thesauri in an effort to augment our ... because the word enhancement carries with it ... Marketroid-speak for a bug fix. ... A hacker being ironic would instead call the fix a feature -- ...
    (comp.cad.solidworks)
  • Re: Looking for the antonym for enhancement - A SolidWords study.
    ... from dictionaries and thesauri in an effort to augment our ... because the word enhancement carries with it ... Marketroid-speak for a bug fix. ... A hacker being ironic would instead call the fix a feature -- ...
    (comp.cad.solidworks)
  • Looking for the antonym for enhancement - A SolidWords study.
    ... because the word enhancement carries with it ... Marketroid-speak for a bug fix. ... Common marketroid-speak for a bug fix. ... A hacker being ironic would instead call the fix a feature -- ...
    (comp.cad.solidworks)