OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: recompile sshd with OPIE?

From: Joel Hatton (joelauscert.org.au)
Date: Tue Aug 16 2005 - 02:04:36 CDT


> freebsd-securityauscert.org.au writes:
> > This may sound like a really silly question, but how do I enable it?
>
> ChallengeResponseAuthentication Yes

Aah - silly me - I always associated that with PAM. I'll try this asap -
holiday tomorrow so in a day or two.

> > There's no man[5] sshd_config entry,

Sorry, I meant there's no mention of OPIE in man[5] sshd_config - as soon
as I read my email I thought it could be misinterpreted :)

> > but through trial and error I
> > identified an option that doesn't cause an error: SkeyAuthentication yes
>
> Which FreeBSD version are you running? There is no such option in any
> recent OpenSSH version, and unrecognized options should cause a fatal
> error.

5.3Rp20 - I found this option just by random guessing, it didn't cause an
error and the daemon started ok! Didn't work though...

thanks very much,
-- Joel Hatton --
Security Analyst | Hotline: +61 7 3365 4417
AusCERT - Australia's national CERT | Fax: +61 7 3365 7031
The University of Queensland | WWW: www.auscert.org.au
Qld 4072 Australia | Email: auscertauscert.org.au
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"