Re: letting root in only from one host

From: Ric Anderson (ric@opus1.com)
Date: 02/28/03


From: "Ric Anderson" <ric@opus1.com>
Date: Fri, 28 Feb 2003 07:30:03 -0700


"Ric Anderson" <ric@opus1.com> wrote in message news:b3lrs6$976$1@oasis.ccit.arizona.edu...
> Under Solaris 8, using .rhosts and rsh, and setting
> CONSOLE=/dev/console
> in /etc/default/login, I can admit root to HOSTB from
> HOSTA. root is not admitted from other hosts,
> although ordinary users are.
>
> I'm trying to effect this same scenario with OpenSSH
> 3.5p1. While I have the user side working just fine,
> I haven't found a combination of settings that will
> admit root only from HOSTA. If I set
> PermitRootLogin yes
> in sshd_config, root is allowed to log in from any
> host that is allowed to connect by tcp wrappers.
> I've tried various combinations of AllowUsers
> and Deny, but haven't come up with anything
> that will admit non-root users from any host, while
> only admitting root from HOSTA.
>
> Has someone else solved this problem, or is there
> no solution?
>
> Thanks,
> ric@opus1.com

Found the answer while looking for something else...
    PermitRootLogin without-password
does exactly what I needed. This means that password auth for
root is -never- accepted so root gets in by host based or not at all.
Ric



Relevant Pages

  • User Mode Linux = Network Problem
    ... For UML, root filesystem is Debian 3.0, ip adress 192.168.1.101, ... On the host: ... Initializing software serial port version 1 ... Configuring network interfaces: done. ...
    (comp.os.linux.networking)
  • User Mode Linux = Network Failed !
    ... For UML, root filesystem is Debian 3.0, ip adress 192.168.1.101, ... On the host: ... Initializing software serial port version 1 ... Configuring network interfaces: done. ...
    (comp.os.linux.development.system)
  • Re: Anglo-Saxon Plant-Name Survey
    ... find a host they quickly die; if they do find a host ... Whether they used the 'root' may be a matter of definition: ... See e.g. this real Broomrape http://tinyurl.com/ndooo ... how about the ground seeds and we are ...
    (soc.history.medieval)
  • Re: Cant ping into or outof Redhat box
    ... There is no host from an arp -n command, ... and neither computer will load iptables. ... | Your basic network setup is not right, ...
    (comp.os.linux.networking)
  • Re: Cant ping into or outof Redhat box
    ... There is no host from an arp -n command, ... and neither computer will load iptables. ... | Your basic network setup is not right, ...
    (linux.redhat)