From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Date: Wed, 23 Jun 2010 03:45:23 +0400 From: "Dmitry V. Levin" To: ALT Linux Sisyphus discussions Message-ID: <20100622234523.GG18232@wo.int.altlinux.org> Mail-Followup-To: ALT Linux Sisyphus discussions References: <20100622214400.GA22145@wo.int.altlinux.org> <20100622225300.GZ14081@osdn.org.ua> <20100622230857.GB18232@wo.int.altlinux.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="kadn00tgSopKmJ1H" Content-Disposition: inline In-Reply-To: X-fingerprint: FE4C 93AB E19A 2E4C CB5D 3E4E 7CAB E6AC 9E35 361E Subject: Re: [sisyphus] I: openssh-server-5.3p1-alt2: disabled PasswordAuthentication for "wheel" group members X-BeenThere: sisyphus@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: ALT Linux Sisyphus discussions List-Id: ALT Linux Sisyphus discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 22 Jun 2010 23:45:23 -0000 Archived-At: List-Archive: List-Post: --kadn00tgSopKmJ1H Content-Type: text/plain; charset=koi8-r Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Jun 23, 2010 at 03:32:46AM +0400, Evgeny Sinelnikov wrote: > 23 =C9=C0=CE=D1 2010 =C7. 3:08 =D0=CF=CC=D8=DA=CF=D7=C1=D4=C5=CC=D8 Dmitr= y V. Levin =CE=C1=D0=C9=D3=C1=CC: > > On Wed, Jun 23, 2010 at 01:53:00AM +0300, Michael Shigorin wrote: > >> On Wed, Jun 23, 2010 at 01:44:00AM +0400, Dmitry V. Levin wrote: > >> > =F7 =F3=C9=DA=C9=C6 =CF=D4=D0=D2=C1=D7=CC=D1=C5=D4=D3=D1 openssh-ser= ver-5.3p1-alt2, =D7 =CB=CF=D4=CF=D2=CF=CD =D0=CF > >> > =D5=CD=CF=CC=DE=C1=CE=C9=C0 =C1=D5=D4=C5=CE=D4=C9=C6=C9=CB=C1=C3=C9= =D1 =D0=CF =D0=C1=D2=CF=CC=C0 =C2=D5=C4=C5=D4 =D7=D9=CB=CC=C0=DE=C5=CE=C1 = =C4=CC=D1 =DE=CC=C5=CE=CF=D7 > >> > =C7=D2=D5=D0=D0=D9 wheel. > >> > >> =F0=D2=C9 =CF=C2=CE=CF=D7=CC=C5=CE=C9=C9 =D5=CD=CF=CC=DE=C1=CE=C9=C5 = =C9=DA=CD=C5=CE=C9=D4=D3=D1 =D0=CF =D3=D2=C1=D7=CE=C5=CE=C9=C0 =D3 =D0=D2= =C5=C4=D9=C4=D5=DD=C9=CD, > >> =C5=D3=CC=C9 /etc/openssh/sshd_config =CE=C5 =D4=D2=CF=C7=C1=CC=D3=D1? > > > > =E4=C1, =CB=CF=CE=C5=DE=CE=CF. > > > >> > =F0=CF=C4=D2=CF=C2=CE=C5=C5 =CF=C2 =DC=D4=CF=CD =D3=CD. > >> > https://bugzilla.altlinux.org/show_bug.cgi?id=3D17286 > >> > >> =F0=CF-=CD=CF=C5=CD=D5, =C9=C4=C5=D1 =CE=C9=CB=D5=C4=C1 =CE=C5 =C7=CF= =C4=C9=D4=D3=D1 =D7 =CB=C1=DE=C5=D3=D4=D7=C5 =D5=CD=CF=CC=DE=C1=CE=C9=D1, = =CB=CF=D4=CF=D2=CF=C5 > >> =CD=CF=D6=C5=D4 =D3=C1=CD=CF=D0=D2=CF=C9=DA=D7=CF=CC=D8=CE=CF =D0=CF= =CD=C5=CE=D1=D4=D8=D3=D1 =D0=D2=C9 =CF=C2=CE=CF=D7=CC=C5=CE=C9=C9 =C4=C9=D3= =D4=D2=C9=C2=D5=D4=C9=D7=C1 > >> =D3 =D0=CF=D4=C5=CE=C3=C9=C1=CC=D8=CE=D9=CD DoS. > > > > =F1 =CE=C5 =D7=C5=D2=C0, =DE=D4=CF =CB=D4=CF-=D4=CF =C5=DD=A3 =D3=CF=DA= =CE=C1=D4=C5=CC=D8=CE=CF =C9=D3=D0=CF=CC=D8=DA=D5=C5=D4 PasswordAuthenticat= ion, > > =CE=CF =CE=C1 =D7=D3=D1=CB=C9=CA =D3=CC=D5=DE=C1=CA =D1 =DC=D4=CF =C9= =DA=CD=C5=CE=C5=CE=C9=C5 =C1=CE=CF=CE=D3=C9=D2=CF=D7=C1=CC. > > > > =EC=C9=DE=CE=CF =D1 PasswordAuthentication =CE=C1 =D3=C5=D2=D7=C5=D2=C5= =C9=D3=D0=CF=CC=D8=DA=D5=C0 =C9=D3=CB=CC=C0=DE=C9=D4=C5=CC=D8=CE=CF =D4=CF= =C7=C4=C1, > > =CB=CF=C7=C4=C1 =CD=CE=C5 =CE=D5=D6=CE=CF =D0=D2=CF=D4=C5=D3=D4=C9=D2= =CF=D7=C1=D4=D8 =DC=D4=CF=D4 =D2=C5=D6=C9=CD =D2=C1=C2=CF=D4=D9 =D0=D2=C9 = =D0=CF=C4=C7=CF=D4=CF=D7=CB=C5 =CE=CF=D7=CF=CA > > =D7=C5=D2=D3=C9=C9 openssh. > > > >> =EB=C1=CB =CE=C5=C4=C5=C6=CF=CC=D4=CE=D9=CA =D7=C1=D2=C9=C1=CE=D4 =C4= =CC=D1 control, =D7 =C9=C4=C5=C1=CC=C5 =D3=D7=D1=DA=C1=CE=CE=D9=CA =D3 cont= rol > >> sudo wheelonly =C1-=CC=D1 slave alternatives -- =C4=C1, =C2=D9=CC=CF = =C2=D9 =C8=CF=D2=CF=DB=CF > >> =C9 =D3=C1=CD =C2=D9 =D0=CF=CC=D8=DA=CF=D7=C1=CC=D3=D1. > >> > >> =F0=D2=CF=DB=D5 =C5=DD=A3 =D2=C1=DA =D0=CF=C4=D5=CD=C1=D4=D8. > > > > =F1 =D7=CF=CF=C2=DD=C5 =D3=CF=C2=C9=D2=C1=CC=D3=D1 =D7=D9=CB=CC=C0=DE= =C9=D4=D8 PasswordAuthentication =D0=CF =D5=CD=CF=CC=DE=C1=CE=C9=C0, =C9, > > =C5=D3=CC=C9 =C2=D9 =CE=C5 =CE=C1=D4=CB=CE=D5=CC=D3=D1 =CE=C1 =CB=CF=CD= =D0=D2=CF=CD=C9=D3=D3=CE=D9=CA =D7=C1=D2=C9=C1=CE=D4, =CF=D0=C9=D3=C1=CE=CE= =D9=CA =D7 #17286, > > =D4=CF =D4=C1=CB =C2=D9 =C9 =D3=C4=C5=CC=C1=CC. > > >=20 > =F5 =CE=C5 =DE=CC=C5=CE=CF=D7 =C7=D2=D5=D0=D0=D9 wheel =D4=CF=D6=C5 =CE= =C5=CD=C1=CC=CF =D7=CF=DA=CD=CF=D6=CE=CF=D3=D4=C5=CA =D3=C4=C5=CC=C1=D4=D8 = =D0=CC=CF=C8=CF. =F4=C5=CD > =C2=CF=CC=C5=C5, =DE=D4=CF =D0=C1=D2=CF=CC=C9 =D5 =D4=C1=CB=C9=C8 "=CE=C5= =D2=D5=CC=D1=DD=C9=C8" =D0=CF=CC=D8=DA=CF=D7=C1=D4=C5=CC=C5=CA =CD=CF=C7= =D5=D4 =C2=D9=D4=D8 > =CE=C5=D5=C4=C1=DE=CE=CF =D0=CF=D4=C5=D2=D1=CE=CE=D9=CD=C9 =C9=CC=C9 =C4= =C1=D6=C5 =D0=CC=CF=C8=C9=CD=C9 =D3 =C2=CF=CC=D8=DB=C5=CA =D3=D4=C5=D0=C5= =CE=D8=C0 =D7=C5=D2=CF=D1=D4=CE=CF=D3=D4=C9, > =DE=C5=CD =D5 "=D2=D5=CC=D1=DD=C9=C8". =EB=C1=CB =D0=D2=C9=CD=C5=D2 =CE= =C5=D5=C4=C1=DE=CE=CF=CA =D0=D2=C1=CB=D4=C9=CB=C9, =C9=CD=C5=C0 =CF=D0=D9= =D4 =D0=CF=CC=D5=DE=C5=CE=C9=D1 > =C2=CF=D4=C1 =C9 =D5=D3=C1=D3=D9=D7=C0=DD=C5=C7=CF =D0=CF=CD=C5=C7=C1=C2= =C1=CA=D4=CE=D9=CA =D4=D2=C1=C6=C9=CB =D3 =D0=D1=D4=CE=C9=C3=D9 =D0=CF =D7= =D4=CF=D2=CE=C9=CB. >=20 > =EE=D5, =D4=C1=CB =DE=D4=CF =D0=CF =D0=CF=D7=CF=C4=D5 =C7=D2=D5=D0=D0=D9 = remote =C9 =D0=CF=CC=C9=D4=C9=CB=C9 "=CB=CF=CD=D5 =CD=CF=D6=CE=CF" =C4=D5= =CD=C1=C5=D4=D3=D1? >=20 > =F1 =C4=D5=CD=C1=C0, =DE=D4=CF =D3=D4=CF=C9=D4 =C4=CF=C2=C1=D7=C9=D4=D8: > =C1) =D0=CF=CC=C9=D4=C9=CB=D5 "=CB=CF=CD=D5 =CD=CF=D6=CE=CF" =D0=CF =C7= =D2=D5=D0=D0=C5, =CE=C1=D0=D2=C9=CD=C5=D2 remote; > =C2) =D0=CF=CC=C9=D4=C9=CB=D5 =D0=CF =CB=C1=DE=C5=D3=D4=D7=D5 =D0=C1=D2= =CF=CC=D1 =CE=C1 auth. >=20 > =EB=C1=CB =D3=C4=C5=CC=C1=D4=D8 =C2) =D1 =D0=CF=CB=C1 =CE=C5 =DA=CE=C1=C0= (=CE=C5 =D0=D2=CF=C2=CF=D7=C1=CC =C4=CF=D3=D4=C1=D4=CF=DE=CE=CF =C1=CB=D4= =C9=D7=CE=CF, =DE=D4=CF=C2=D9 > =D0=CF=CC=D5=DE=C9=CC=CF=D3=D8), =CE=CF =D4=CF=D6=C5 =CF=DE=C5=CE=D8 =C2= =D9 =C8=CF=D4=C5=CC. >=20 > =E7=D2=D5=D0=D0=C1 remote =D0=CF=CB=D2=D9=D7=C1=C5=D4 =C2=CF=CC=D8=DB=C5 = =D2=C1=C2=CF=DE=C9=C8 =D3=C3=C5=CE=C1=D2=C9=C5=D7, =DE=C5=CD =D0=D2=CF=D3= =D4=CF "=D0=CF > =CB=CC=C0=DE=C1=CD". =ED=C1=CC=CF =CC=C9 =D5 =CB=CF=C7=CF =CB=CC=C0=DE=C9= =CC=C5=D6=C1=D4, =D0=CF =D3=D4=C1=D2=CF=CA =D0=C1=CD=D1=D4=C9... >=20 > =F1 =D7=C9=D6=D5 =D4=C1=CB=C9=C5 =D3=C3=C5=CE=C1=D2=C9=C9: > 1) =EE=CF=D7=D9=CA. > - =DE=CC=C5=CE=D9 =C7=D2=D5=D0=D0=D9 wheel "=C8=CF=C4=D1=D4" =D4=CF=CC=D8= =CB=CF =D0=CF =CB=CC=C0=DE=C1=CD; > - =CF=D3=D4=C1=CC=D8=CE=D9=C5, =CB=C1=CB =C8=CF=D4=D1=D4. > 2) =ED=CF=CA =D4=C5=CB=D5=DD=C9=CA. > - "=C8=CF=C4=D1=D4" =D4=CF=CC=D8=CB=CF =DE=CC=C5=CE=D9 =C7=D2=D5=D0=D0=D9= remote; > - =CF=D3=D4=C1=CC=D8=CE=D9=C5 "=CE=C5 =C8=CF=C4=D1=D4". > 3) =E7=C9=C2=D2=C9=C4=CE=D9=CA =D0=C5=D2=D7=D9=CA. > - "=C8=CF=C4=D1=D4" =D4=CF=CC=D8=CB=CF =DE=CC=C5=CE=D9 =C7=D2=D5=D0=D0=D9= remote; =F5 =CD=C5=CE=D1 =D3=C1=CD=D9=CA =D2=C1=D3=D0=D2=CF=D3=D4=D2=C1=CE=A3=CE=CE= =D9=CA =D3=C3=C5=CE=C1=D2=C9=CA =D7=C9=C4=C1 PasswordAuthentication no AllowGroups wheel users (=C4=CF=D3=D4=D5=D0 =C9=CD=C5=C0=D4 =D4=CF=CC=D8=CB=CF =DE=CC=C5=CE=D9 =C7= =D2=D5=D0=D0 wheel =C9 users =C9 =D4=CF=CC=D8=CB=CF =D0=CF =CB=CC=C0=DE=C1= =CD) =CF=D4=CC=C9=DE=C1=C5=D4=D3=D1 =CF=D4 =D0=C5=D2=C5=DE=C9=D3=CC=C5=CE=CE=D9= =C8 =D7=C1=CD=C9. =F7=CF=CF=C2=DD=C5, =CF=D3=CD=D9=D3=CC=C5=CE=CE=D9=C8 =D3=C3=C5=CE=C1=D2=C9= =C5=D7 =CD=CF=D6=C5=D4 =C2=D9=D4=D8 =D7=C5=CC=C9=CB=CF=C5 =CD=CE=CF=D6=C5= =D3=D4=D7=CF, =D1 =C2=D9 =CE=C5 =D0=D9=D4=C1=CC=D3=D1 =DA=C1=D3=D5=CE=D5=D4=D8 =C9=C8 =D7=D3=C5=C8 =D7 =CB=CF=CE=C6=C9=C7. =ED=CF=D6=CE=CF =CE=C1=D2=C9=D3=CF=D7=C1=D4=D8 =CB=C1=CB=C9=C5-=CE=C9=C2=D5= =C4=D8 control sshd-password-auth enabled|disabled|nonwheel control sshd-allow-groups enabled|disabled|=C9=CD=D1_=C7=D2=D5=D0=D0=D9 =CE=CF =D1 =CE=C5 =D5=D7=C5=D2=C5=CE, =DE=D4=CF =CF=CE=CF =D4=CF=C7=CF =D3= =D4=CF=C9=D4. --=20 ldv --kadn00tgSopKmJ1H Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkwhSxMACgkQfKvmrJ41Nh57yACdG/Yxfq94PGwIXh8oP59EJG+d TOIAn2nUR92QpVFixMEkHJFM5U4P5H3+ =IR7T -----END PGP SIGNATURE----- --kadn00tgSopKmJ1H--