Public key authentication and logging

This is a discussion on Public key authentication and logging within the OpenSSH Development forums, part of the Networking and Network Related category; Hello, [This message has been sent previously to the ssh-users list, but got no answer, so maybe it's ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-02-2005
Nestor Burma
 
Posts: n/a
Default Public key authentication and logging

Hello,

[This message has been sent previously to the
ssh-users list, but got no answer, so maybe it's not a
usage problem. Sorry for the crossposting]

We are using OpenSSH 4.1p1 on a Linux box. The only
authentication method allowed is by public key.
Everything works without any problem, EXCEPT logging
in one situation :

1/ if a known user tries to log, with a proper (known)
key, as expected, we get a success message through
syslog, such as
:

Accepted publickey for USER from IP

2/ if an unknow user tries to log (obviously with or
without a "proper key"), again as expecte, we get a
failure message through syslog, such as :

Invalid user USER from IP

3/ but if a KNOWN user tries to log without a known
key, we get no message whatsoever.

Taking into account all the current brute forcing
tools, we feel this is somehow wrong. Of course, we
get bazillions of failures for unknown users, but
unfortunately some tools we saw just hammered 'root'
and a few, well-known account names. So getting no
failure message is bad for us.

Is it a misconfiguration on our part ? And if so, how
to change that ?

Sincerely,

-- Nb











__________________________________________________ ___________________________
Découvrez le nouveau Yahoo! Mail : 1 Go d'espace de stockage pour vos mails, photos et vidéos !
Créez votre Yahoo! Mail sur http://fr.mail.yahoo.com

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://www.mindrot.org/mailman/listi...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:05 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0