Re: HP-UX openssh configuration problem

From: Owen T. Stevens (otstevens_at_adelphia.net)
Date: 08/22/03

  • Next message: Richard Caley: "Re: Solution for botnets"
    Date: Thu, 21 Aug 2003 22:57:31 GMT
    
    

    The problem that your libpam_unix needs to be patched, because OpenSSH and many
    others do not understand HPs broken chauthok(). This is also fixed, along with
    various other problems, with HPs distribution of ssh.

    To fix this using the latter method, remove your installation of openssh and replace
    it with HPs distribution, from http://www.software.hp.com/ISS_products_list.html
    (listed as hpux secure shell). You may also remove your installation of zlib and
    openssl, unless you are using those packages for something in addition to ssh. I
    would also strongly recommend installing the random number generator (/dev/random) if
    you have 11.11 or greater. Otherwise ssh will be S-L-O-W waiting for prng (pseudo
    random number generator) all the time.

    Presto Change-o, and it will work.

    Hope this Helps,

    Owen T. Stevens

    Ken McGinnis wrote:
    > I'm currently running HP-UX 11.00 with OpenSSH_3.6.1p1. My problem is when
    > a users account is about to expire it does not notify the user that you have
    > X amount of days left before the password expires or even on the day of
    > expire make the user change the password when logging in via SSH.
    >
    >
    >
    >
    > Any help on this would be great.
    >
    > Ken
    >
    >


  • Next message: Richard Caley: "Re: Solution for botnets"

    Relevant Pages

    • Re: HP-UX openssh configuration problem
      ... with HPs distribution of ssh. ... To fix this using the latter method, remove your installation of openssh and replace ... unless you are using those packages for something in addition to ssh. ... > expire make the user change the password when logging in via SSH. ...
      (comp.sys.hp.hpux)
    • solaris password aging problem
      ... I'm using openssh 3.4p1 compiled --with-pam on solaris 8. ... to get keyboard-interactive auth to work, but if I expire a user's password ... he will never be able to change it using ssh. ...
      (comp.security.ssh)
    • Re: two SSH compatibility scenarios: can it work?
      ... We are required to use SSH to log into the Engineering lab machines. ... > server software displays this header upon telnet connection to port 22. ... I still use Windows on my notebook for application compatibility. ... > running OpenSSH 3.4p1. ...
      (comp.security.ssh)
    • Re: OpenSSH, Telnet, Windows Authentication and double-hops
      ... deployment on a Windows network. ... Does this mean that you are setting SSH port forwarding ... does not provide the other side with either a Kerberos ticket, ... We're focusing on the OpenSSH for Windows distribution. ...
      (comp.security.ssh)
    • Re: [openssh-unix-announce] Re: Upcoming OpenSSH vulnerability (fwd)
      ... Is OpenSSH 3.3 now part of the base system? ... older versions of ssh are vulnerable or not. ... I have to say that I side with Theo here: ... we wouldn't need OpenSSH. ...
      (FreeBSD-Security)