opensshd-3.1p1 works on one machine, broken on the next...?

From: Archie Campbell (archie.campbell@ntlworld.com)
Date: 05/16/02


From: archie.campbell@ntlworld.com (Archie Campbell)
Date: 15 May 2002 15:15:47 -0700

Ssh compadres,

Whatever can be the problem if I am suddenly able to login as root
when

PermitRootLogin no
AND
DenyUsers root

?

There can be no doubt that something fundamentally and ludicrously
simple has been overlooked when I have copied the (fully satisfactory)
sshd_config file from firewall to devel machine, and then find the
problem has not dissipated, like so much malodorous effluent gas, but
has persisted, like a problem in your sshd that won't go away.

A state of blind panic has ensued, and since I should rather shoot
myself in the head than root around (no pun intended) amongst the
openssh tree, especially in said state, I throw the problem
google-wide, and hope for a benign response.

Incidentally, I'm so goddamned proud of that firewall that I invite
anyone who can link my email address to an IP to have a damned good go
at it. Moreover, I'm on nearly 12 hours a day, so don't crack me
unless you enjoy separating /dev/random contents from the output of
your various and vicarious cracking tools, whatever UTC happens to be.

Regards,

Archie "DON'T PANIC" Campbell



Relevant Pages

  • opensshd-3.1p1 works on one machine, broken on the next...?
    ... Whatever can be the problem if I am suddenly able to login as root ... PermitRootLogin no ... DenyUsers root ... I'm so goddamned proud of that firewall that I invite ...
    (comp.security.ssh)
  • Re: lifecyle?
    ... settings that allow one to run as actual root. ... when going online. ... to go online with Linux until I find an easy, ... clear, GUI-based, 2-way firewall. ...
    (microsoft.public.vb.general.discussion)
  • Re: Certificate authorities and firewalls
    ... Make the SA Root certificate and CRLs outside of the firewall ... extension to include an externally accessible location where the CRLs and CA ... If the firewall does not allow the SARootCA machine to publish to these two ...
    (microsoft.public.win2000.security)
  • Re: OT - Desktop Linux
    ... Disable logging remote logging to SSH as root, add a user that does not ... tion-based firewall solution. ... Look at the default installation ruleset of industrial strength firewall ...
    (alt.sports.basketball.nba.la-lakers)
  • Re: root kits on linux
    ... provided you use a good secure root ... SUSE has a good firewall. ... It does not matter wether it takes 1 year or 1 ... Now I have something that works with cron, but cron is just not fast ...
    (alt.os.linux.suse)