Re: Force non-empty pass-phrase?



Paul Hink wrote:
mark <mark@xxxxxxxxxx> wrote:

I guess it would be possible to write a script for root to traverse
over unix users client side home areas attempting to do some kind of
ssh-keygen operation on their keys and confirming that a pass-phrase
is prompted for?

I would not allow any SSH server to execute arbitrary code with the
permissions of my client side user account. (And this could not
prevent "malicious" users from deliberately using a key with a blank
passphrase either. The client could always manipulate the server's
control process and its environment.)

I've done that as an administrator in NFS based environments, and given
users gentle warnings about NFS published home directories with no password
SSH keys in them. It's a serious no-no in such an environment, since anyone
can pretend to be the user with a simple NFS client and access all their
files.


.



Relevant Pages

  • Re: D3 b-tree problem
    ... Pushing a tool past the limits of what ... dates to gather the required keys. ... using D3's ability to see the spooler entries as a regular item. ... > I have a client who is experiencing some problems with SELECTs on a very ...
    (comp.databases.pick)
  • Re: Enterprose Manager after user password change
    ... XP client machines with a non-Domain account. ... > registered servers when the user's network password is changed. ... Saving the keys and restoring ... > password should be written to the registry. ...
    (microsoft.public.sqlserver.security)
  • Re: Client connect without host service running?
    ... Incoming clients cannot connect via ssh unless openssh is running. ... openssh caches the keys in memory... ... I went to the ssh client and compared the host ...
    (comp.security.ssh)
  • Re: Best Practice: Table Primary Key
    ... Do not create keys on the client side and allow the database to solve ... Use MSDE on the client and work up replication between client and server. ... > Should I 'never use an AutoIncrement again'? ...
    (microsoft.public.dotnet.framework.adonet)
  • passwordless ssh logins _STILL_ not working - help needed.
    ... I am trying to allow _all users_ on CLIENT to login to ... SERVER without a password. ... I am not interested in user keys _at all_ ...
    (freebsd-questions)