OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
sshd_config and pam...

From: Darren Reed (darrenrnetbsd.org)
Date: Thu Jul 30 2009 - 00:49:27 CDT


I don't know if this is known or not, but it appears that enabling PAM
in your sshd_conf file makes entries such as "PasswordAuthentication"
meaningless. With PAM enabled, I was able to login with ssh using a
password even with the aforementioned setting at "no".

Is it worthwhile adding some sort of warning to sshd that spits out a
message of some sort about this if UsePAM is set to yes and there
are other authentication driven directives present and not commented
out?

Darren