From owner-freebsd-current@FreeBSD.ORG Wed Mar 25 12:49:19 2009 Return-Path: Delivered-To: current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0C238106566B for ; Wed, 25 Mar 2009 12:49:19 +0000 (UTC) (envelope-from ianf@clue.co.za) Received: from inbound01.jnb1.gp-online.net (inbound01.jnb1.gp-online.net [41.161.16.135]) by mx1.freebsd.org (Postfix) with ESMTP id 969E38FC17 for ; Wed, 25 Mar 2009 12:49:18 +0000 (UTC) (envelope-from ianf@clue.co.za) Received: from [196.7.162.28] (helo=clue.co.za) by inbound01.jnb1.gp-online.net with esmtpsa (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.63) (envelope-from ) id 1LmSXj-0000rQ-43; Wed, 25 Mar 2009 14:49:15 +0200 Received: from localhost ([127.0.0.1] helo=clue.co.za) by clue.co.za with esmtp (Exim 4.69 (FreeBSD)) (envelope-from ) id 1LmSXe-000IqH-QM; Wed, 25 Mar 2009 14:49:10 +0200 To: barney_cordoba@yahoo.com From: Ian FREISLICH In-Reply-To: <995845.90009.qm@web63905.mail.re1.yahoo.com> References: <995845.90009.qm@web63905.mail.re1.yahoo.com> X-Attribution: BOFH Date: Wed, 25 Mar 2009 14:49:10 +0200 Message-Id: Cc: Ruben de Groot , Chuck Robey , current@freebsd.org Subject: Re: Telnet root login X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 25 Mar 2009 12:49:19 -0000 Barney Cordoba wrote: > > Barney, you have to make the network pseudo ttys secure, > > like: > > > > ttyp0 none network secure > > > > Ruben > > Yes, the "its not a good idea" is dependent on whatever other > security you have in place. Having to log in twice to a test > machine on a secure internal network is an unnecessary annoyance. > The concept that every FreeBSD box in existence is publically accessible > is one of those ASSumptions that people should leave at the door. > > Ruben, the method you cite no longer works in -current as they've > changed things once again (which happens way too often when your CEOs > are a bunch of bearded academics :) > > I'm not sure if its the pty (the login terminal shows as pty/0 and > no longer ttyp0), or if its some PAM thing. Its rather annoying. > Such things as > > pty/0 none network secure > pty0 none network secure > > equally don't work. And I see no mention in any document as to how it > would be achieved with the current Then use ssh and set "PermitRootLogin yes" in /etc/ssh/sshd_config Ian -- Ian Freislich