From owner-freebsd-stable Wed Jul 25 20:22:54 2001 Delivered-To: freebsd-stable@freebsd.org Received: from edgemaster.zombie.org (cx497943-d.omhaw1.ne.home.com [24.3.233.212]) by hub.freebsd.org (Postfix) with ESMTP id 6975837B403 for ; Wed, 25 Jul 2001 20:22:48 -0700 (PDT) (envelope-from smkelly@zombie.org) Received: by edgemaster.zombie.org (Postfix, from userid 1001) id 191C4103A03; Wed, 25 Jul 2001 22:23:34 -0500 (CDT) Date: Wed, 25 Jul 2001 22:23:34 -0500 From: Sean Kelly To: stable@freebsd.org Subject: PR bin/25586 still burns Message-ID: <20010725222333.A1522@edgemaster.zombie.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="n8g4imXOkfNTN/H1" Content-Disposition: inline User-Agent: Mutt/1.3.19i Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --n8g4imXOkfNTN/H1 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Recently, I've come to experience the bug noted in PR bin/25586 (http://www.freebsd.org/cgi/query-pr.cgi?pr=3D25586). When a user with an expired password attempts to SSH into the system, sshd/pam pours gallons of Jul 25 23:02:23 area51 sshd[82877]: PAM pam_chauthtok failed[6]: Permission denied Jul 25 23:02:23 area51 sshd[82877]: no modules loaded for `sshd' service messages into syslog. thinking it might be my PAM or OpenSSH, I did a buildworld/buildkernel/installkernel/installworld/mergemaster last night and have made no headway on the problem. It still happens as of last night, and yes pam.conf is up to date and identical to /usr/src/etc/pam.conf. Does anybody know anything more about this problem since the PR was last updated a month ago? This seems like a serious issue to me. FreeBSD ... 4.3-STABLE FreeBSD 4.3-STABLE #0: Wed Jul 25 06:37:35 EDT 2001 root@...:/usr/obj/usr/src/sys/KERNEL i386 sshd auth sufficient pam_skey.so #sshd auth sufficient pam_kerberosIV.so try_first_pass sshd auth required pam_unix.so try_first_pass sshd session required pam_permit.so # "csshd" is for challenge-based authentication with sshd (TIS auth, etc.) csshd auth required pam_skey.so --=20 Sean Kelly | PGP KeyID: 77042C7B smkelly@zombie.org | http://www.zombie.org For PGP key, send e-mail with subject "send pgp key" --n8g4imXOkfNTN/H1 Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) iD8DBQE7X4012aukpHcELHsRApBqAJ4rEfEqc7XjSFKLBQHVDKVq9ub2pgCggxdb AiIYC5vXh+d8P/fM21kfpk8= =mhYg -----END PGP SIGNATURE----- --n8g4imXOkfNTN/H1-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message