Re: Authentication restrictions per account?
From: w4Ciabvd nyzLnN (bu4+A_@ZW%!.com)Date: 09/08/02
- Next message: : "automatic login with password authentication only"
- Previous message: those who know me have no need of my name: "Re: Authentication restrictions per account?"
- In reply to: those who know me have no need of my name: "Re: Authentication restrictions per account?"
- Next in thread: Dimitri Maziuk: "Re: Authentication restrictions per account?"
- Reply: Dimitri Maziuk: "Re: Authentication restrictions per account?"
- Reply: : "Re: Authentication restrictions per account?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: bu4+A_@ZW%!.com (w4Ciabvd nyzLnN) Date: Sun, 08 Sep 2002 14:55:45 GMT
In article <m18z2dyy0j.gnus@usa.net>,
those who know me have no need of my name <not-a-real-address@usa.net> wrote:
>in comp.security.ssh i read:
>
>>And, I should worry about bad file system corrupting my keys?
>
>if you find a way of making the key the only way to login, then of course
>you should be worried about it becoming corrupted.
The point which apparently eluded the O.P. is regardless of
the authentication method, there remains an array of other
possibilities which could lead to failure. What if the root file
system was corrupted (i.e. the passwd file trashed)? For years and
years, /etc/passwd was the only way to login to a Unix host. What if
my $HOME file system failed to fsck so that it failed to mount?
If $HOME is exported from another host, what if NFS is somehow hosed?
I recall in other Unix flavors (read: don't know how this relates
to Linux) that if the utmp file was removed or truncated, no
logins would be permitted. There are a myriad of ways to prevent a
successful login. I do not see how or why allowing an individual
user to apply a subset of the AllowedAuthentications is perceived as
so ominous. The individual has the means to "inconvenience"
themselves via other ways (e.g. using a from lines in the
authorized_keys, forced commands, etc., etc.).
>because there is no way, currently. hack the source to provide yourself an
>indicator. if you do not control the server (as seems the case) then you
>will just have to live with password access remaining possible. you could
>ask the admins to disable it, but i doubt they will.
I believe I'll try the latter as the former may violate my TOS.
- Next message: : "automatic login with password authentication only"
- Previous message: those who know me have no need of my name: "Re: Authentication restrictions per account?"
- In reply to: those who know me have no need of my name: "Re: Authentication restrictions per account?"
- Next in thread: Dimitri Maziuk: "Re: Authentication restrictions per account?"
- Reply: Dimitri Maziuk: "Re: Authentication restrictions per account?"
- Reply: : "Re: Authentication restrictions per account?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|