From owner-freebsd-questions@FreeBSD.ORG Wed Jan 14 19:10:51 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5934016A4CE for ; Wed, 14 Jan 2004 19:10:51 -0800 (PST) Received: from hobbiton.shire.net (hobbiton.shire.net [206.71.64.250]) by mx1.FreeBSD.org (Postfix) with ESMTP id 60BED43D1D for ; Wed, 14 Jan 2004 19:10:49 -0800 (PST) (envelope-from chad@shire.net) Received: from [67.161.247.57] (helo=[192.168.99.66]) by hobbiton.shire.net with asmtp (TLSv1:RC4-SHA:128) (Exim 4.10) id 1AgxuC-0006HD-00 for questions@freebsd.org; Wed, 14 Jan 2004 20:10:48 -0700 Mime-Version: 1.0 (Apple Message framework v609) In-Reply-To: <4005F03E.3010808@theatre.msu.edu> References: <130d319f1f.19f1f130d3@etat.lu> <4005F03E.3010808@theatre.msu.edu> Message-Id: <696E4A56-4708-11D8-84FF-003065A70D30@shire.net> From: "Chad Leigh -- Shire.Net LLC" Date: Wed, 14 Jan 2004 20:10:46 -0700 To: FreeBSD-questions X-Mailer: Apple Mail (2.609) Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on hobbiton.shire.net X-Spam-Status: No, hits=-4.9 required=5.0 tests=BAYES_00 autolearn=no version=2.60 X-Spam-Level: Subject: Re: sshd, how is this possible, security bug? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 15 Jan 2004 03:10:51 -0000 On Jan 14, 2004, at 6:43 PM, Jonathan T. Sage wrote: > > you did. from ssh's point of view. however, pam is enabled, and it > allows password authentication. to do what you're asking, edit > sshd_config again, and toggle this line > > # Change to no to disable PAM authentication > ChallengeResponseAuthentication no > > this is my fix, it allows only pubkey logins. i'm sure this is also > possible with PAM, and actually, would love to know how that works too > :) Does anyone have any idea on how to require a pubkey AND a password? I don't want either one to be enough, but want both... Thanks Chad