Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

priviledge seperation not working like before

From: <list1(at)0ff.org>
Date: Thu Feb 13 2003 - 01:17:29 EST


Hello--

I just realized that my previously installed sshd is NOT using privilege separation..So..I went to reconfigure it, and make sure it was working correctly.

Configure:

./configure --with-tcp-wrappers --with-md5-passwords --with-pam --with-privsep-path=/var/empty --with-privsep-user=sshd

Yes, sshd exists, yes /var/empty exists, yes yes yes..

my current sshd_conf does reads:

PAMAuthenticationViaKbdInt no <-- per the README.privsep and
UsePrivilegeSeparation yes <-- obvious

and here is the current ps aux | grep sshd:

root     24673  0.0  0.1  2644 1156 ?        S    Feb12   0:00 /usr/sbin/sshd
root       254  0.0  0.2  3412 1644 ?        S    Feb12   0:00 /usr/sbin/sshd
where     5321  0.0  0.2  3468 1876 ?        S    Feb12   0:00 /usr/sbin/sshd
Do you need help?X

(pids are randomized, btw)

I am at a loss, configure shows no errors, make works, etc.. One thing I noticed that was most odd was that substituting a NON-existent user in place of sshd in the above configuration did NOT produce an error

ssh version is OpenSSH_3.5p1
linux box running 2.4.19-grsecurity kernel that _has_ had this working before

any help appreciated, thanks in advance,

Cherie Received on Thu Feb 13 15:17:17 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:54 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library