Re: It's not possible to allow non-OPIE logins only from trusted

看板FB_security作者時間14年前 (2011/03/25 19:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串26/26 (看更多)
Sex, 2011-03-11 =C3=A0s 21:15 +0000, Miguel Lopes Santos Ramos escreveu: > Here's a scratch. >=20 > I added an option, called "require_trusted", which enforces the trusted > network check even for users which do not have OPIE enabled. > If this option is not used, behaviour is unchanged. >=20 > The name "require_trusted" is catchy and compeling to use. However, if > it was used in default configuration files, login would be impossible > (unless there was a default opieaccess file which permitted everything, > but that is bit forcing OPIE stuff on people and it's not worth it).=20 Well, this thread got a bit lost discussing other issues: So, any comments on the usefulness of this patch? I'm undecided myself, when I saw that I can easily lock everyone out with this (however, that's usually the case with other pam modules). With this option: - Non-OPIE logins are only possible from trusted networks (those in /etc/opieaccess), - Consequently, users which do not have OPIE enabled can only log in from trusted networks, - Consequently, if /etc/opieaccess does not exist, users which do not have OPIE enabled cannot log in (I see valid uses for this, anyway) - Consequently, if no one has OPIE enabled, no one can log in (thus optimum security is achieved). Overall, I think this is useful. I think I'm not the only one in this situation. One basic reason for this is that most users on my network very rarelly need shell access and even more rarelly they need it from outside. Having complex passwords becomes hard to manage, as a user who logs in once every three months will never remember he's password. Account lockout is also not what I want. --=20 Miguel Ramos <mbox@miguel.ramos.name> PGP A006A14C _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1DZ7qp_G (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 26 之 26 篇):
文章代碼(AID): #1DZ7qp_G (FB_security)