Re: openssh in stable-10 broken config or sandbox

看板FB_stable作者時間11年前 (2014/03/04 03:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/9 (看更多)
On 03/01/14 02:39, Andrey Chernov wrote: > On 01.03.2014 10:56, Andrey Chernov wrote: >> Hi. >> Default /etc/ssh/sshd_config have >> #UsePrivilegeSeparation sandbox >> I.e. 'sandbox' by default. It breaks logins with error: >> sshd[81721]: fatal: ssh_sandbox_child: failed to limit the network socket [preauth] >> Fixed by using old way, i.e. direct >> UsePrivilegeSeparation yes >> instead of 'sandbox'. Please fix this bug. > Just find that capsicum is required now for default (i.e. sandbox) mode. > Don't think it is wise move, people may lost remote connections that > way, at least UPDATING entry is needed, but check for WITHOUT_CAPSICUM > for defaults will be better. > Personally I find this to be a monumental screw up, such a drastic change and not even so much as an entry in UPDATING, what ever happened to POLA? _______________________________________________ freebsd-stable@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-stable To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org"
文章代碼(AID): #1J5DYoG2 (FB_stable)
討論串 (同標題文章)
文章代碼(AID): #1J5DYoG2 (FB_stable)