From owner-freebsd-stable@FreeBSD.ORG Wed Nov 21 00:20:53 2007 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 1F9EF16A419 for ; Wed, 21 Nov 2007 00:20:53 +0000 (UTC) (envelope-from jdc@parodius.com) Received: from mx01.sc1.parodius.com (mx01.sc1.parodius.com [72.20.106.3]) by mx1.freebsd.org (Postfix) with ESMTP id 1731113C468 for ; Wed, 21 Nov 2007 00:20:52 +0000 (UTC) (envelope-from jdc@parodius.com) Received: by mx01.sc1.parodius.com (Postfix, from userid 1000) id 8B3341CC079; Tue, 20 Nov 2007 16:20:43 -0800 (PST) Date: Tue, 20 Nov 2007 16:20:43 -0800 From: Jeremy Chadwick To: "Julian H. Stacey" Message-ID: <20071121002043.GA98340@eos.sc1.parodius.com> References: <474325A0.7060802@gmail.com> <200711202315.lAKNFa4R012904@fire.js.berklix.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200711202315.lAKNFa4R012904@fire.js.berklix.net> User-Agent: Mutt/1.5.16 (2007-06-09) Cc: freebsd-stable@freebsd.org, "Aryeh M. Friedman" Subject: Re: Software for distribution of configuration files and changes X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Nov 2007 00:20:53 -0000 On Wed, Nov 21, 2007 at 12:15:36AM +0100, Julian H. Stacey wrote: > Add > PermitRootLogin yes > to > /etc/ssh/sshd_config This should really be "PermitRootLogin without-password". Yes, the phrase "without-password" looks scary, but it isn't so much -- it allows root login via passwordless SSH keys only, while simultaneously continues disallowing root logins via keyboard/password authentication. sshd_config(5) has details. -- | Jeremy Chadwick jdc at parodius.com | | Parodius Networking http://www.parodius.com/ | | UNIX Systems Administrator Mountain View, CA, USA | | Making life hard for others since 1977. PGP: 4BD6C0CB |