OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Vincent Danen (vdanenmandrakesoft.com)
Date: Fri Mar 23 2001 - 17:50:12 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Fri Mar 23, 2001 at 06:08:19PM -0500, jon wrote:

    > Is anyone experiencing any PAM problems with the OpenSSH update which
    > was just released?
    >
    > Mandrake 7.1
    >
    > pam-0.72-7.1mdk
    > openssh-askpass-2.5.2p2-1.2mdk
    > openssh-2.5.2p2-1.2mdk
    > openssh-clients-2.5.2p2-1.2mdk
    > openssh-server-2.5.2p2-1.2mdk
    >
    > I get a permission denied when attempting login via UNIX shadow file
    > auth (password).
    >
    > Haven't looked into fixing it yet, I just noticed.

    You shouldn't have a problem since those packages were built against
    the appropriate versions of pam and should have the correct
    /etc/pam.d/ssh file. Just double-checking it here and it should work
    just fine... Have you restarted the server?

    On a side note, a number of things in the configs have changed, so you
    might want to go into /etc/ssh and rename the *.rpmnew files to their
    normal counterparts (ssh_config and sshd_config). That might help.

    > PS- I think that was a great response to the new SSH findings. They are
    > already implementing that tool into dsniff which just adds to the importance
    > of being aware of all types of vulnerabilities!

    Yup... it also allows 7.2 and older distribs to talk to cooker/8.0 as
    well, which is an added benefit.

    -- 
    vdanenmandrakesoft.com, OpenPGP key available on www.keyserver.net
    1024D/FE6F2AFD   88D8 0D23 8D4B 3407 5BD7  66F9 2043 D0E5 FE6F 2AFD
     - Danen Consulting Services    www.danen.net, www.freezer-burn.org
     - MandrakeSoft, Inc. Security  www.linux-mandrake.com
    

    Current Linux kernel 2.4.2-13mdk uptime: 4 days 0 hours 16 minutes.

    -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org

    iD8DBQE6u+E0IEPQ5f5vKv0RAmZoAKCT0RLyg3N+GhE7r80oJsuUfuy5QACgh0DK EkOyIGR6BIplU9yTdp2O0go= =em1u -----END PGP SIGNATURE-----