OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: 4.x, PAM, password facility

From: Peter Pentchev (roamringlet.net)
Date: Mon Jun 21 2004 - 01:54:31 CDT


On Fri, Jun 18, 2004 at 04:26:19PM -0400, Charles Sprickman wrote:
[snip]
> And since I know there's someone lurking here that knows this, is there
> any way to have OpenSSH deny a login when a user has key-based auth setup
> on their account? I never found a good way to take care of that; changing
> the shell, etc. is a bit awkward.

The sshd_config(5) manual page for OpenSSH in both -STABLE and -CURRENT
mentions Allow/DenyUsers/Groups. I'm not sure how long this has been
around, though - I seem to remember a time when only ssh.com's sshd
supported this.

G'luck,
Peter

--
Peter Pentchev roamringlet.net roamsbnd.net roamFreeBSD.org
PGP key: http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint FDBA FD79 C26F 3C51 C95E DF9E ED18 B68D 1619 4553
If I had finished this sentence,

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFA1oYn7Ri2jRYZRVMRAje2AJ4wd5wLCtHvydb0dep9R+wNEC91xgCgjNZW
xeS9uf3BIby0zk/Vkdm3GU4=
=4WmR
-----END PGP SIGNATURE-----