From owner-freebsd-current@FreeBSD.ORG Wed Oct 31 15:38:12 2007 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 750BD16A420; Wed, 31 Oct 2007 15:38:12 +0000 (UTC) (envelope-from des@des.no) Received: from tim.des.no (tim.des.no [194.63.250.121]) by mx1.freebsd.org (Postfix) with ESMTP id 2F9E613C4A8; Wed, 31 Oct 2007 15:38:12 +0000 (UTC) (envelope-from des@des.no) Received: from tim.des.no (localhost [127.0.0.1]) by spam.des.no (Postfix) with ESMTP id 5665E208D; Wed, 31 Oct 2007 16:37:17 +0100 (CET) X-Spam-Tests: AWL X-Spam-Learn: disabled X-Spam-Score: -0.0/3.0 X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on tim.des.no Received: from ds4.des.no (des.no [80.203.243.180]) by smtp.des.no (Postfix) with ESMTP id D453C2088; Wed, 31 Oct 2007 16:37:16 +0100 (CET) Received: by ds4.des.no (Postfix, from userid 1001) id CEE8484462; Wed, 31 Oct 2007 16:37:16 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: Jeremy Chadwick References: <20071027101312.GA42516@eos.sc1.parodius.com> <86bqafxt96.fsf@ds4.des.no> <20071031143944.GB21646@eos.sc1.parodius.com> Date: Wed, 31 Oct 2007 16:37:16 +0100 In-Reply-To: <20071031143944.GB21646@eos.sc1.parodius.com> (Jeremy Chadwick's message of "Wed\, 31 Oct 2007 07\:39\:44 -0700") Message-ID: <867il3xplf.fsf@ds4.des.no> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.1 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-current@freebsd.org, Rob Zietlow Subject: Re: [7.0-Beta] can no longer ssh into just upgraded host X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 31 Oct 2007 15:38:12 -0000 Jeremy Chadwick writes: > Dag-Erling Sm=C3=B8rgrav wrote: > > What makes you think it might be PAM-related? They don't even get as > > far as exchanging version strings. > An old -stable post I read is what made me think it might be > PAM-related: > > http://lists.freebsd.org/pipermail/freebsd-stable/2004-November/009414.ht= ml The symptoms are completely different. > I don't know what stage PAM is actually induced within sshd (are any > PAM-related API calls done before version exchange, etc.). No. The client and server send their version string in plain text immediately upon establishing a TCP connection. PAM isn't initialized until after they have agreed on algorithms and keys and decided which authentication method to use. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no