Possible bug in openssh parsing of hosts.equiv for netgroups?

This is a discussion on Possible bug in openssh parsing of hosts.equiv for netgroups? within the OpenSSH Development forums, part of the Networking and Network Related category; Open-SSH'ers, I just noticed that ssh doesn't parse hosts.equiv the same as rsh. I set up ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2005
Alek O. Komarnitsky
 
Posts: n/a
Default Possible bug in openssh parsing of hosts.equiv for netgroups?

Open-SSH'ers,

I just noticed that ssh doesn't parse hosts.equiv the same as rsh.
I set up an usertest user on targethost, and then su'ed to usertest
on sourcehost. I put this in targethost's /etc/hosts.equiv
+ -usertest
+@trusted-hosts (all hosts are rolled up into this netgroup)
this should disallow usertest from rsh'ing into targethost from all
hosts, but then allow any other users to rsh into targethost without
a password as long as they have a login on targethost.

What I found was that when I did the rsh from sourcehost, I got
prompted for a password, but when I did the ssh it let me in without
a password. Try a "man hosts.equiv" to see an explanation of what
I'm doing with the "+ -usertest".


I looked at the openssh3.9p1 source code for auth-rhosts.c and
around line 100, it looks like there is a bug in that the same
"negated" variable is used for both the host and user checks as
it loops/parses the hosts.equiv file, but seems to me that if one
is denied access because of an explicit rule, you should be disallowed in.


Would be curious if anyone agree with my interpretation of this
behavior and pointer to possible bug in the hosts.equiv parsing?
Thanx,
alek

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://www.mindrot.org/mailman/listi...enssh-unix-dev
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:30 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0