Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 26 Jun 2002 13:31:46 -0700
From:      Gregory Sutter <gsutter@zer0.org>
To:        "Andrew R. Reiter" <arr@watson.org>, Dirk Meyer <dinoex@FreeBSD.org>
Cc:        cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   Re: cvs commit: ports/security/openssh Makefile pkg-plist
Message-ID:  <20020626203146.GA56167@klapaucius.zer0.org>
In-Reply-To: <Pine.NEB.3.96L.1020626000223.9732H-100000@fledge.watson.org>
References:  <200206260401.g5Q412c68657@freefall.freebsd.org> <Pine.NEB.3.96L.1020626000223.9732H-100000@fledge.watson.org>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
On 2002-06-26 00:03 -0400, "Andrew R. Reiter" <arr@watson.org> wrote:
> On Tue, 25 Jun 2002, Dirk Meyer wrote:
> 
> :dinoex      2002/06/25 21:01:02 PDT
> :
> :  Modified files:
> :    security/openssh     Makefile pkg-plist 
> :  Log:
> :  Small cleanups for smoothlees migration to $PREFIX/etc/shh
> :  
> :  Revision  Changes    Path
> :  1.100     +9 -8      ports/security/openssh/Makefile
> :  1.21      +4 -5      ports/security/openssh/pkg-plist
> 
> Why the hell have there been so many commits to this port at a time when
> we KNOW everyone will be doing updates (soley out of paranoia)?

Dirk updated the port quickly to OpenSSH 3.3, then fixed it up to use
PrivSep and (as the above commit log shows) to make migrations to the
new layout easier.  I know, because I rebuilt OpenSSH on five machines
after _each_ time he updated the port... and I'm currently doing the
same with the 3.4 upgrade.  GRRR!  :)

Thanks much for staying on top of the changes to OpenSSH, Dirk.  May
I suggest the following patch to sshd_config to make our default
configuration more secure:

--- sshd_config Wed Jun 26 13:26:46 2002
+++ sshd_config.new     Wed Jun 26 13:28:24 2002
@@ -31,7 +31,7 @@
 # Authentication:
 
 #LoginGraceTime 600
-#PermitRootLogin yes
+PermitRootLogin no
 #StrictModes yes
 
 #RSAAuthentication yes
@@ -54,8 +54,8 @@
 #PasswordAuthentication yes
 #PermitEmptyPasswords no
 
-# Change to no to disable s/key passwords
-#ChallengeResponseAuthentication yes
+# Change to yes to enable s/key passwords
+ChallengeResponseAuthentication no
 
 # Kerberos options
 #KerberosAuthentication no
@@ -74,9 +74,7 @@
 #PrintLastLog yes
 #KeepAlive yes
 #UseLogin no
-UseLogin yes
 #UsePrivilegeSeparation yes
-UsePrivilegeSeparation yes
 #Compression yes
 
 #MaxStartups 10


Greg
-- 
Gregory S. Sutter                                    Fnord.
mailto:gsutter@zer0.org 
http://www.zer0.org/~gsutter/ 
hkp://wwwkeys.pgp.net/0x845DFEDD

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----
Comment: ''

iD8DBQE9GiSyIBUx1YRd/t0RAmd2AJ0Y5IJmSDZTplCFO9fGtverSojCugCeJbk8
hX5a7qs/5R2SlswMhhwx3ik=
=eRac
-----END PGP SIGNATURE-----
home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020626203146.GA56167>