Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Question regarding allow and deny users

From: James Dennis <jdennis(at)law.harvard.edu>
Date: Fri Feb 28 2003 - 09:52:34 EST

Hello Samaresh,

> 1. If a user is put in allow user's list, can the same be put in the deny user's list also? If

Bad idea, just don't do it.

> 2. If a user is not put in both the lists, is he given access rights? Lets say a user is not

If there are no Allow/Deny directives all access is allowed (the default). If you place AllowUsers james in sshd_config, then only james is allowed to access the system and everyone else is denied. If you you place DenyUsers james, the default of allowing everyone into the system is still there, but james is denied.

See OpenSSH's mailing list archive for information regarding questionable behavior of how Allow/Deny Users/Groups behaves. Ben Lindstrom was kind enough to fix the behavior for OpenSSH's current source and I modified his patch to work for OpenSSH's 3.5 release (I just changed line numbers, Ben is still the code wizard).

Also, for any more confusion, please check the man. This stuff is written up pretty clearly in there.

Do you need help?X

http://www.openbsd.org/cgi-bin/man.cgi?query=sshd_config

-- 
James Dennis
Harvard Law School

"Not everything that counts can be counted,
and not everything that can be counted counts."
Received on Fri Feb 28 22:13:18 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:55 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library