Re: disabled account accepting publickey authentication

From: Brian Whitehead (brian@whiteheadconsulting.com)
Date: 01/06/03


From: brian@whiteheadconsulting.com (Brian Whitehead)
Date: 6 Jan 2003 10:46:45 -0800

slade@shore.net (Richard E. Silverman) wrote in message news:<m1l8yxyapcu.fsf@syrinx.oankali.net>...
> >>>>> "BW" == Brian Whitehead <brian@whiteheadconsulting.com> writes:
>
> BW> I've found that an system account that I had disabled has been
> BW> able to authenticate with a ssh publickey...
>
> What do you mean by "disabled?"

By disabled I mean simply that the account has the ! in the shadow
file by using 'usermod -L'.

To me this would be a bug. An administrator should not have to jump
through hoops to disable all access to a machine for a specific user.
Simply disabling the primary account should disable everything
including ssh.



Relevant Pages

  • RE: Scavanging retired machine accounts
    ... Here's a script I wrote a while back that does exactly what you want. ... 'pull back a list of every user's account name and distinguished name ... we're probably only interested in the disabled computer accounts ... 'There is no point disabling PCs based on how many weeks it's been since the ...
    (microsoft.public.windows.server.scripting)
  • Re: "Enabling" an already enabled user account?
    ... Is that user having problems in all machines or just that one? ... (Logon failure: account currently disabled. ... see Help and Support Center at ... > I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • RE: Why should we disable local administrator accounts?
    ... I understand that you have concerns on disabling local Administrator ... Account on client workstations in SBS domain. ... At least if your local admin passwords are ...
    (microsoft.public.windows.server.sbs)
  • Re: "Enabling" an already enabled user account?
    ... ASF Gigabit Ethernet Controller ... I logged onto the account using another machine ... Windows cannot access the file gpt.ini for GPO ... I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Enabling" an already enabled user account?
    ... I've checked both DCs and there are no replication errors. ... (Logon failure: account currently disabled. ... I've tried actually disabling the account and then re-enabling and with ... The event log has nothing specific to the cause, ...
    (microsoft.public.windows.server.active_directory)