From owner-freebsd-bugs Fri May 4 9:30: 8 2001 Delivered-To: freebsd-bugs@hub.freebsd.org Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by hub.freebsd.org (Postfix) with ESMTP id 1864A37B424 for ; Fri, 4 May 2001 09:30:01 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.11.1/8.11.1) id f44GU1j41533; Fri, 4 May 2001 09:30:01 -0700 (PDT) (envelope-from gnats) Received: from aldan.algebra.com (aldan.algebra.com [216.254.65.224]) by hub.freebsd.org (Postfix) with ESMTP id 11A6137B424 for ; Fri, 4 May 2001 09:22:33 -0700 (PDT) (envelope-from mi@aldan.algebra.com) Received: (from mi@localhost) by aldan.algebra.com (8.11.3/8.11.3) id f44GOZ723909; Fri, 4 May 2001 12:24:35 -0400 (EDT) (envelope-from mi) Message-Id: <200105041624.f44GOZ723909@aldan.algebra.com> Date: Fri, 4 May 2001 12:24:35 -0400 (EDT) From: Mikhail Teterin Reply-To: mi@aldan.algebra.com To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.113 Subject: bin/27080: sshd may mis-parse the authorized_keys file Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org >Number: 27080 >Category: bin >Synopsis: sshd may mis-parse the authorized_keys file >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Fri May 04 09:30:00 PDT 2001 >Closed-Date: >Last-Modified: >Originator: Mikhail Teterin >Release: FreeBSD 4.3-BETA i386 >Organization: Virtual Estates, Inc. >Environment: FreeBSD raidbox.privatelabs.com 4.3-BETA FreeBSD 4.3-BETA #0: Tue Apr 10 20:30:55 EDT 2001 mi@minime.privatelabs.com:/raid/src/sys/compile/RAIDBOX i386 >Description: I have some keys in the authorized_keys file with some limitational flags: no-pty,no-port-forwarding,no-agent-forwarding 1024 35 ..key... If add another key _after_ this one, the flags seem to apply to it too, even though its line does not have them. no-pty is the most noticable one. >How-To-Repeat: Put a couple of keys with no-pty,no-port-forwarding and no-agent-forwarding flags in front of your regular keys. See, if you can still login normally. >Fix: Make sure the keys with the special flags are at the bottom of the file. Not a complete work-around, since the flags may be mixed for different keys. >Release-Note: >Audit-Trail: >Unformatted: To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message