From owner-freebsd-current@FreeBSD.ORG Wed Sep 12 14:48:46 2007 Return-Path: Delivered-To: freebsd-current@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D620816A41A for ; Wed, 12 Sep 2007 14:48:46 +0000 (UTC) (envelope-from bsam@ipt.ru) Received: from mail.ipt.ru (mail.ipt.ru [194.62.233.102]) by mx1.freebsd.org (Postfix) with ESMTP id 8065F13C45D for ; Wed, 12 Sep 2007 14:48:46 +0000 (UTC) (envelope-from bsam@ipt.ru) Received: from admin.sem.ipt.ru ([192.168.12.1] helo=ipt.ru) by mail.ipt.ru with esmtp (Exim 4.62 (FreeBSD)) (envelope-from ) id 1IVTWH-000ECJ-7w; Wed, 12 Sep 2007 18:48:45 +0400 Received: from bsam by ipt.ru with local (Exim 4.63 (FreeBSD)) (envelope-from ) id 1IVTXS-0001N4-N3; Wed, 12 Sep 2007 18:49:58 +0400 To: "Poul-Henning Kamp" References: <18073.1189607975@critter.freebsd.dk> From: Boris Samorodov Date: Wed, 12 Sep 2007 18:49:58 +0400 In-Reply-To: <18073.1189607975@critter.freebsd.dk> (Poul-Henning Kamp's message of "Wed\, 12 Sep 2007 14\:39\:35 +0000") Message-ID: <07763369@srv.sem.ipt.ru> User-Agent: Gnus/5.11 (Gnus v5.11) Emacs/22.0.99 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: freebsd-current@FreeBSD.org Subject: Re: sshd and a "command" option at ~/.ssh/authorized_keys X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Sep 2007 14:48:46 -0000 On Wed, 12 Sep 2007 14:39:35 +0000 Poul-Henning Kamp wrote: > In message <89849832@srv.sem.ipt.ru>, Boris Samorodov writes: > >With 'command="/bin/echo You are $USER!"' at ~/.ssh/authorized_keys: > >$ ssh > >You are duser! <-- is'a real username > > > >But with 'command="/bin/echo You invoked $SSH_ORIGINAL_COMMAND!"': > >$ ssh > >You invoked ! > >^^^^^^^^^^^^^ > >Is this a bug? (Yes, I know about security issues etc.) > Try: > ssh you_need_to_give_a_command_to_actually_see_it Well, I see I'm a moron. :-( Poul-Henning, thank you for you kind answer. WBR -- Boris Samorodov (bsam) Research Engineer, http://www.ipt.ru Telephone & Internet SP FreeBSD committer, http://www.FreeBSD.org The Power To Serve