Re: how to get rid of sshd needing DNS ?

From: Darren Tucker (dtucker_at_dodgy.net.au)
Date: 04/27/04


Date: Tue, 27 Apr 2004 00:32:52 +0000 (UTC)

In article <c6j69g$npk$1@at-vie-newsmaster01.nextra.at>,
Thomas Wolf <tw@wsf.at> wrote:
>This one is driving me crazy.
>I dont want my sshd to lookup the client's IP.
>Turned off VerifyReverseMapping, running sshd with -n0,

-u0 is what you probably want.

>not using all the items listed in the manpage that
>could cause a lookup but no luck. Any hints ?
>BTW, this is on FreeBSD 4.9-RELEASE-p4.

I don't know which version is in FreeBSD, but recent OpenSSH's also have
a UseDNS sshd_config option.

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


Relevant Pages

  • Re: sshd. "UseDNS no" ignored?
    ... "UseDNS no" only prevents sshd from performing a validation ... of the client's reverse lookup. ... that it will not put hostnames into the utmp structure ...
    (freebsd-stable)
  • Re: how would openssh react face to an attack ?
    ... >but how would it react face to an attack? ... account after X password failures. ... if the OS doesn't support lockout then sshd doesn't either. ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: ssh initial connects SLOW
    ... attempted *logging* of the hostname of the connecting site, ... information ot 0 does, in fact, block the lookup. ... documented in the sshd manpage. ... would have been easy to modify the code to check for the UseDNS ...
    (comp.security.ssh)
  • Re: telnet tunnelling ssh
    ... >That host has ssh package installed and sshd up and running. ... >(All looks silly but it's the truth) ... >connection already established? ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: AIX 5.3 LDAP PAM PrivilegeSeperation
    ... > If we run sshd in non-privilegeseperation mode, ... > expiry, when a user is REQUIRED to change the password, when a new ... Good judgement comes with experience. ...
    (comp.security.ssh)