From owner-freebsd-security@FreeBSD.ORG Fri Mar 11 10:03:17 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A2C34106564A for ; Fri, 11 Mar 2011 10:03:17 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id 623548FC13 for ; Fri, 11 Mar 2011 10:03:17 +0000 (UTC) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id 0026A1FFC33; Fri, 11 Mar 2011 09:46:08 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id C315284550; Fri, 11 Mar 2011 10:46:08 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Miguel Lopes Santos Ramos References: <1299682310.17149.24.camel@w500.local> Date: Fri, 11 Mar 2011 10:46:08 +0100 In-Reply-To: <1299682310.17149.24.camel@w500.local> (Miguel Lopes Santos Ramos's message of "Wed, 09 Mar 2011 14:51:50 +0000") Message-ID: <86aah2yopr.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.2 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: It's not possible to allow non-OPIE logins only from trusted networks X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Mar 2011 10:03:17 -0000 Miguel Lopes Santos Ramos writes: > 1. The user does not have OPIE enabled and the remote host is listed as > a trusted host in /etc/opieaccess. > 2. The user has OPIE enabled and the remote host is listed as a trusted > host in /etc/opieaccess, and the user does not have a file > named .opiealways in his home directory. > > Or at least this should be an option for pam_opieaccess. Seems like a good idea, at first blush (provided it's optional). Do you have a patch? DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no