<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>17286</bug_id>
          
          <creation_ts>2008-09-23 00:33:48 +0400</creation_ts>
          <short_desc>[FR] group wheel with PasswordAuthentication disabled by default</short_desc>
          <delta_ts>2010-06-23 11:20:41 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>openssh-server</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ivan Zakharyaschev">imz</reporter>
          <assigned_to name="Gleb F-Malinovskiy">glebfm</assigned_to>
          <cc>aen</cc>
    
    <cc>asy</cc>
    
    <cc>cas</cc>
    
    <cc>glebfm</cc>
    
    <cc>ldv</cc>
    
    <cc>mike</cc>
    
    <cc>vitty</cc>
    
    <cc>vt</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>78455</commentid>
    <comment_count>0</comment_count>
      <attachid>2943</attachid>
    <who name="Ivan Zakharyaschev">imz</who>
    <bug_when>2008-09-23 00:33:48 +0400</bug_when>
    <thetext>Created attachment 2943
sshd_config-wheel-without-password.diff

openssh-server-4.7p1-alt1

I suggest a more secure default configuration for consideration:

Match Group wheel
    PasswordAuthentication no

It continues the logic of the default &quot;PermitRootLogin without-password&quot;: it disables the login with password for group wheel. The drawback is that it might irritate some users who are in the group wheel, if their systems are not exposed to the corresponding dangers (of guessing the password for known usernames by intruders).

If it is decided that this configuration is not appropriate as a default, it could still be exposed in comments or as an option in the default configuration tool (alterator?) in order to be of some use.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>110034</commentid>
    <comment_count>1</comment_count>
    <who name="Michael Shigorin">mike</who>
    <bug_when>2010-06-23 02:52:55 +0400</bug_when>
    <thetext>(In reply to comment #0)
&gt; I suggest a more secure default configuration for consideration:
I object to this being a default, and strongly object to changing such a default without prior public debate.

&gt; If it is decided that this configuration is not appropriate as a default, it
&gt; could still be exposed in comments
Definitely.

&gt; or as an option in the default configuration
&gt; tool (alterator?) in order to be of some use.
control(8) I believe.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>110035</commentid>
    <comment_count>2</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-06-23 02:57:09 +0400</bug_when>
    <thetext>openssh-5.3p1-alt2 -&gt; sisyphus:

* Wed Jun 23 2010 Dmitry V. Levin &lt;ldv@altlinux&gt; 5.3p1-alt2
- Enabled sftp by default.
- /etc/pam.d/sshd: Changed to use common-login.
- sshd_config: Disabled PasswordAuthentication for &quot;wheel&quot; group
  members (imz@; closes: #17286).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>110044</commentid>
    <comment_count>3</comment_count>
    <who name="Sergey Y. Afonin">asy</who>
    <bug_when>2010-06-23 11:20:41 +0400</bug_when>
    <thetext>Hm... What about another way ?

https://bugzilla.altlinux.org/show_bug.cgi?id=11669</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>2943</attachid>
            <date>2008-09-23 00:33:48 +0400</date>
            <delta_ts>2008-09-23 00:33:48 +0400</delta_ts>
            <desc>sshd_config-wheel-without-password.diff</desc>
            <filename>sshd_config-wheel-without-password.diff</filename>
            <type>text/plain</type>
            <size>1951</size>
            <attacher name="Ivan Zakharyaschev">imz</attacher>
            
              <data encoding="base64">SSB3YXNuJ3QgaGFwcHkgd2l0aCB0aGUgaWRlYSB0aGF0IGFuIGludHJ1ZGVyIGZyb20gdGhlIElu
dGVybmV0IGNvdWxkCmdldCByb290IGluIHRoaXMgc3lzdGVtIGJ5IHBhc3N3b3JkLWd1ZXNzaW5n
LgoKV2VsbCwgb25lLXN0ZXAgcGFzc3dvcmQgZ3Vlc3NpbmcgaXMgZXhjbHVkZWQgYnkgdGhlICJ3
aXRob3V0LXBhc3N3b3JkIgpwb2xpY3kgZm9yIFBlcm1pdFJvb3RMb2dpbi4gQnV0IHR3by1zdGVw
IHBhc3N3b3JkLWd1ZXNzaW5nIHdhcyBzdGlsbApwb3NzaWJsZSB2aWEgYSB1c2VyIGZyb20gdGhl
IGdyb3VwIHdoZWVsLiBUbyBzdHJlbmd0aGVuIHRoZSBzZWN1cml0eQpieSBleGNsdWRpbmcgdGhp
cyBwb3NzaWJpbGl0eSwgSSBtYWRlIHRoZSBjb25maWd1cmF0aW9uIGJlbG93LgoKVGhlIGVmZmVj
dCBvZiB0aGF0IGRpcmVjdGl2ZSBpcyBub3QgZXhhY3RseSB0aGUgc2FtZSBhcyBvZiAKIlBlcm1p
dFJvb3RMb2dpbiB3aXRob3V0LXBhc3N3b3JkIjogdW5kZXIgdGhlICJ3aXRob3V0LXBhc3N3b3Jk
Igpwb2xpY3ksIHRoZSBwYXNzd29yZCBpcyBzdGlsbCByZXF1ZXN0ZWQgb24gbG9naW4gYXR0ZW1w
dHMsIGJ1dCB0aGUKbG9naW4gc2ltcGx5IG5ldmVyIHN1Y2NlZWRzIHdpdGggYSBwYXNzd29yZC4g
VW5kZXIgdGhlIAoiUGFzc3dvcmRBdXRoZW50aWNhdGlvbiBubyIgc2V0dXAsIHRoZSBwYXNzd29y
ZCBtZXRob2QgaXMgbm90IApzdWdnZXN0ZWQgb24gYSBsb2dpbiBhdHRlbXB0IGF0IGFsbCBmb3Ig
dGhlIGdyb3VwIHdoZWVsLgoKT25lIHNpZGUtZWZmZWN0IG9mIHRoaXMgY29uZmlndXJhdGlvbiBp
cyB0aGF0IHRoZSBwYXNzd29yZCBpcyBub3QKcmVxdWVzdGVkIGZvciByb290IGFzIHdlbGwgYW55
bW9yZSAoaWYgcm9vdCBpcyBpbiBncm91cCB3aGVlbCkuIFNvLAp0aGlzIGNvbmZpZ3VyYXRpb24g
d291bGQgdW5mb3J0dW5hdGVseSBkaXNjbG9zZSBzb21lIGJpdHMgb2YgCmluZm9ybWF0aW9uIGFi
b3V0IHRoZSByZWFsIGNvbmZpZ3VyYXRpb24gb2Ygc3NoZC4KCklmIHRoaXMgY29uZmlndXJhdGlv
biBpcyBtYWRlIHRoZSBkZWZhdWx0LCB0aGVyZSBpcyBhIGRyYXdiYWNrIGZvcgp1c2VycyBvZiAi
cGVyc29uYWwiIGNvbXB1dGVycyB3aGljaCB3aWxsIG5ldmVyIGJlIGV4cG9zZWQgdG8gSW50ZXJu
ZXQ6CmluIHRoZWlyIGxvY2FsIHJlbGF0aXZlbHkgc2FmZSBuZXRzLCB0aGUgdXNlcnMgZnJvbSB0
aGUgZ3JvdXAgd2hlZWwgd2lsbCAKcHJvYmFibHkgYmUgaXJyaXRhdGVkIGJ5IHRoZSBpbXBvc3Np
YmlsaXR5IHRvIGxvZyBpbiB3aXRoIGEgcGFzc3dvcmQuIApCdXQgdGhpcyB0aGluZyBjYW4gYmUg
Y29uZmlndXJhYmxlIHRocm91Z2ggdGhlIGNvbmZpZ3VyYXRpb24gdG9vbCAoYWx0ZXJhdG9yPykK
dXNlZCB0byB0dXJuIHNzaGQgb24gKGJ5IGRlZmF1bHQsIHNzaGQgaXMgdHVybmVkIG9mZiBpbiwg
c2F5LCBBTFQgTGl0ZSA0LjAuMykuCgppbXogYXQgYWx0bGludXgub3JnLgoKLS0tIHNzaGRfY29u
ZmlnLmZhY3RvcnkJMjAwOC0wOS0yMiAyMjoxNDoxOCArMDQwMAorKysgc3NoZF9jb25maWcJMjAw
OC0wOS0yMiAyMjoyMzozNiArMDQwMApAQCAtMzUsNiArMzUsNyBAQAogCiAjTG9naW5HcmFjZVRp
bWUgMm0KICNQZXJtaXRSb290TG9naW4gd2l0aG91dC1wYXNzd29yZAorIyAtLSB0aGlzIHBvbGlj
eSBpcyBleHRlbmRlZCB0byBncm91cCB3aGVlbCAoc2VlIGEgTWF0Y2ggYmVsb3cpLgogI1N0cmlj
dE1vZGVzIHllcwogI01heEF1dGhUcmllcyA2CiAKQEAgLTExNSwzICsxMTYsNyBAQAogIwlYMTFG
b3J3YXJkaW5nIHllcwogIwlBbGxvd1RjcEZvcndhcmRpbmcgbm8KICMJRm9yY2VDb21tYW5kIGN2
cyBzZXJ2ZXIKKworIyBBbiBleHRlbnNpb24gb2YgdGhlIHBvbGljeSAiUGVybWl0Um9vdExvZ2lu
IHdpdGhvdXQtcGFzc3dvcmQiOgorTWF0Y2ggR3JvdXAgd2hlZWwKKyAgICBQYXNzd29yZEF1dGhl
bnRpY2F0aW9uIG5vCg==
</data>

          </attachment>
      

    </bug>

</bugzilla>