Re: HP-UX openssh configuration problem

From: Ken Green (Ken.Green_at_kgcc.co.uk)
Date: 08/21/03


Date: Thu, 21 Aug 2003 11:09:05 +0100

John Prather wrote:

> Maybe this should be checked in a login script like /etc/profile,
> /.cshrc, or something similar?
>
> I'm not familiar with HP's password expiration system, but I'm pretty
> sure that this is not an sshd issue. Forcing users to a password prompt
> to change their password should probably be the responsibility of the
> system which stores account expiration dates, and only occur after the
> password has expired.
>

> -------------------8<-------------------

>
>
> All this is done after sshd hands connection to the user's shell, so all
> the system tools a user could check password expiration with ought to be
> accessible.
>

On HP-UX login looks after password ageing, and I think sshd must
bypasses login. I'd have thought that login was using PAM.

>
> Anyway, good luck!
>
> -john
>
> p.s. to my knowledge, sshd itself has no way of understanding such
> internals of the auth system as when passwords expire, but I could be
> mistaken.
>
> Ken McGinnis wrote:
>



Relevant Pages

  • Re: HP-UX openssh configuration problem
    ... > sure that this is not an sshd issue. ... > the system tools a user could check password expiration with ought to be ... On HP-UX login looks after password ageing, ... > internals of the auth system as when passwords expire, ...
    (comp.sys.hp.hpux)
  • Re: sshd attacks
    ... but if you know the usernames you want you could use ... > from your sshd server before anyone can break your encryption. ... > taht finds open sshd services and tests common user names and password. ... You could also do something where you login with PK to an account whose ...
    (comp.unix.bsd.freebsd.misc)
  • Re: strange and serious problem about user login
    ... > any service other than root. ... > and I try to login as normal user except root, ... > and when I start sshd in this pc, I get no errors, but when I check ...
    (Fedora)
  • Signal 1, Name stays on "who" list under Linux
    ... I'm not too sure if this is off topic, it might be a bug in sshd which is ... OpenSSH v3.4p1, SSH protocols 1.5/2.0 ... 1> connect to the linux box via SSH client and login as any user ... To get past step 2 you have to enter root password, ...
    (comp.security.ssh)
  • Re: autoblocking many ssh failed logins from the same IP....
    ... > daemon) to stop accepting login attempts from a given IP if it tries ... > actually just read the man pages and figure out how to get sshd to ... You can have multiple AllowUsers entries if you want more than one user ... To unsubscribe, ...
    (freebsd-questions)