From owner-freebsd-security Thu Mar 14 15:42:36 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx2.nersc.gov (mx2.nersc.gov [128.55.6.22]) by hub.freebsd.org (Postfix) with ESMTP id C618737B420 for ; Thu, 14 Mar 2002 15:42:26 -0800 (PST) Received: from gemini.nersc.gov (gemini.nersc.gov [128.55.16.111]) by mx2.nersc.gov (Postfix) with ESMTP id 7C8F25924 for ; Thu, 14 Mar 2002 15:42:26 -0800 (PST) Received: from gemini.nersc.gov (localhost [127.0.0.1]) by gemini.nersc.gov (Postfix) with ESMTP id 306E63B1AB for ; Thu, 14 Mar 2002 15:42:26 -0800 (PST) X-Mailer: exmh version 2.5 07/13/2001 with nmh-1.0.4 To: freebsd-security@freebsd.org Subject: Re: sshd UseLogin option In-Reply-To: Your message of Thu, 14 Mar 2002 09:42:53 MST. <15504.54029.424057.761653@caddis.yogotech.com> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="==_Exmh_-317853754P"; micalg=pgp-sha1; protocol="application/pgp-signature" Content-Transfer-Encoding: 7bit Date: Thu, 14 Mar 2002 15:42:26 -0800 From: Eli Dart Message-Id: <20020314234226.306E63B1AB@gemini.nersc.gov> Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --==_Exmh_-317853754P Content-Type: text/plain; charset=us-ascii In reply to Nate Williams : > > > Could someone please explain to me why we don't use sshd's UseLogin > > > option by default? I know that there was a security hole related to > > > that option recently, but that's not a real reason - security holes > > > can show up anywhere - so is there anything that makes UseLogin a > > > particularly bad idea? > > > > Who uses system passwords with ssh(1)? > > We do for our remote access boxes that have numerous users accessing > them. Also, if you want to use sudo, you need to have local passwords. Yes, you can use keys as well, but many folks don't bother. --eli --==_Exmh_-317853754P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: This is a comment. iD8DBQE8kTViLTFEeF+CsrMRAmFEAJoCbUb+fqaej0my6Gw0tcUXs+d3+ACg1ECU FNn2ZF3RLmC8N2aXxY7az3U= =Lj30 -----END PGP SIGNATURE----- --==_Exmh_-317853754P-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message