RE: Disabling ForceCommand in a Match block

This is a discussion on RE: Disabling ForceCommand in a Match block within the OpenSSH Development forums, part of the Networking and Network Related category; At this point, put any testing that you do into the bug (#1315) on the Bugzilla site - other than that, ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-17-2007
Knox, Bill
 
Posts: n/a
Default RE: Disabling ForceCommand in a Match block

At this point, put any testing that you do into the bug (#1315) on the
Bugzilla site - other than that, I guess it's up to the developers to
either

1) include it
2) spot the idiotic oversight in my implementation, modify it and then
include it
3) spot the idiotic oversight in my logic and refuse it

I'm not taking any bets :-)

Thanks, by the way, for the positive feedback.

Bill Knox
Lead Operating Systems Programmer/Analyst
The MITRE Corporation

-----Original Message-----
From: openssh-unix-dev-bounces+wknox=mitre.org@mindrot.org
[mailto:openssh-unix-dev-bounces+wknox=mitre.org@mindrot.org] On Behalf
Of Remy Blank
Sent: Thursday, May 17, 2007 5:43 AM
To: openssh-unix-dev@mindrot.org
Subject: Re: Disabling ForceCommand in a Match block

Knox, Bill wrote:
> Therefore,
> negation won't work for Groups, though it will for the User, Host and
> Address criteria (the same is true for comma separated values for the
> same reason). I've tested this, and it works with the following

setup:
>
> Match User *,!root
> ForceCommand echo "Test"


This is brilliant! It solves my problem much better than my current
workaround:

Match User user1, user2, user3, ...
ForceCommand /usr/bin/validate-command

(As this is a production machine, I didn't dare keep my patch before
getting at least some feedback from people more knowledgeable than I
am).

> I have written a brief patch to implement this. I haven't tested what
> happens with the AllowGroups and DenyGroups cases, but it will work

in
> to force a command for everyone not in the other group as follows:
>
> Match Group *,!other
> ForceCommand echo "Test"


This would completely and elegantly solve my situation. Thanks for
taking the time to implement it. Do you need any testing at this point?

-- Remy

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/lis...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:05 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0