Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Running sshd as normal user

From: Brian Hatch <secureshell(at)ifokr.org>
Date: Fri Aug 08 2003 - 13:21:46 EDT

> I have installed the OpenSSH-daemon (3.6.1p1) with the chroot-patch from

If you don't need to support passwd authentication against /etc/shadow and friends, and instead are comfortable living with identity/pubkey authentication, then you can easily run it as a normal user. However you can't run it on port 22, because only root can bind low ports. Instead you'd need to run it like this

        user$ cp /etc/sshd/sshd_config /home/user/.ssh/sshd_config

        user$ vi /home/user/.ssh/sshd_config

        user$ /usr/sbin/sshd -f /home/user/.ssh/sshd_config -p 2222

or something similar. You'll need to disable privilige separation for this to work as a normal user (since you can't chroot, etc).

Do you need help?X

I haven't tried this recently, but I think privsep and native passwd auth is the only thing that requires you run as root. Give that a try.

--
Brian Hatch                  Language, it's a virus.
   Systems and
   Security Engineer
http://www.ifokr.org/bri/

Every message PGP signed

  • application/pgp-signature attachment: stored
Received on Fri Aug 8 15:25:22 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:01 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library