Re: Rhosts authentication with openssh 3.7

From: Nico Kadel-Garcia (nkadel_at_comcast.net)
Date: 12/03/03


Date: Wed, 3 Dec 2003 08:12:33 -0500


"ludovic LECLERC" <ludovic.leclerc@col.bsf.alcatel.fr> wrote in message
news:773f08cd.0311240733.20dc976d@posting.google.com...
> I know that rhosts based authentication is HEAVILY unsecured but in my
> special case, it would help. I don't like the idea of having a feature
> in a software that disappears one day in a release just because
> someone said "what that f... option ?!? still exists ?... ok let's
> blast it !".
> Someone know if there is a patch to restore this option ? (no it's not
> a joke...).
> Ok, I know the answer... I'll restore the source code from v3.6. I
> like this job !...
>
> thanks
> ludo.

This didn't just "disappear one day". It's been a screaming "don't do that"
issue since the invention of SSH, for years. If you have to run something
that is exactly like rsh with .rhosts, then run rsh with .rhosts.

Seriously, it's so much more secure to use tools like "ssh-agent" if you
need automatic behavior, I strongly recommend them to you.



Relevant Pages

  • Re: Securing command line passwords
    ... On Friday 25 February 2005 11:14, Alvin Oga wrote: ... > use scp ... ... > .rhosts for rsh which you should not use ...
    (Debian-User)
  • Re: RSH & PAM
    ... Hash: SHA1 ... > I am trying to get rsh ... .rhosts is evil and your trust relationship between machines that use ...
    (comp.os.linux.security)
  • Re: RSH & PAM
    ... Hash: SHA1 ... > I am trying to get rsh ... .rhosts is evil and your trust relationship between machines that use ...
    (comp.os.linux.security)
  • Re: rsh moving me to ssh
    ... > I have been told that I have should probably use ssh instead of rsh! ... appropriate .rhosts file I have that 99% of the time it is because the remote ... Unix Guy Consulting, LLC ...
    (comp.unix.questions)
  • Re: Trying to rsh from Win2000 to Tru64 V5.1A - Why doesnt this work ??????
    ... Peter da Silva wrote: ... > It's asking for your password, which means it's not letting you in via ... > rhosts and rsh won't work. ...
    (comp.unix.tru64)