Re: Debian openssh option review: considering splitting out GSS-API key exchange
Marco d'Itri <[email protected]>
| Newsgroups | gmane.linux.debian.devel.ssh,gmane.linux.debian.devel.general |
|---|---|
| Message-ID | <[email protected]> |
On Apr 02, Colin Watson <[email protected]> wrote: > At the time, denyhosts was popular, but it was removed from Debian > several years ago. I remember that, when I dealt with that on my own > systems, fail2ban seemed like the obvious replacement, and my impression > is that it's pretty widely used nowadays; it's very pluggable but it > normally works by adding firewall rules. Are there any similar popular > systems left that rely on editing /etc/hosts.deny? Yes, people. I object to removing TCP wrappers support since the patch is tiny and it supports use cases like DNS-based ACLs which cannot be supported by L3 firewalls. -- ciao, Marco
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQQnKUXNg20437dCfobLPsM64d7XgQUCZgvYKgAKCRDLPsM64d7X gSgmAP9NUok0UnVmvuEdRxRcHrPCBQ+azpTcU8k+CSEZqUwZNgEA07ZBye7avM8M 0ARdn9z03HBGGje0Lyr9rLE64AYoQw8= =6QEV -----END PGP SIGNATURE-----