Bug#163202: marked as done (ssh: ssh with public key authentication seems paranoid about home dir permissions)

"Debian Bug Tracking System" <[email protected]> Tue, 02 Jun 2026 07:35:02 +0000
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1780385702-2213429-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Tue, 02 Jun 2026 07:31:57 +0000
with message-id <[email protected]>
and subject line explained and to broad
has caused the Debian Bug report #163202,
regarding ssh: ssh with public key authentication seems paranoid about home=
 dir permissions
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
163202: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D163202
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1780385702-2213429-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 3 Oct 2002 12:44:48 +0000
Return-path: <[email protected]>
Received: from rhols66.adsl.netsonic.fi (there.afraid.org) [194.29.198.66] 
	by master.debian.org with esmtp (Exim 3.12 1 (Debian))
	id 17x5LT-0003cM-00; Thu, 03 Oct 2002 07:44:47 -0500
Received: from era by there.afraid.org with local (Exim 3.35 #1 (Debian))
	id 17x5LK-0006q2-00
	for <[email protected]>; Thu, 03 Oct 2002 15:44:38 +0300
From: era eriksson <[email protected]>
Subject: ssh: ssh with public key authentication seems paranoid about home dir permissions
To: [email protected]
X-Mailer: bug 3.3.10.1
X-Debbugs-Cc: [email protected]
Message-Id: <[email protected]>
Sender: era eriksson <[email protected]>
Date: Thu, 03 Oct 2002 15:44:38 +0300
Delivered-To: [email protected]

Package: ssh
Version: 1:3.4p1-1
Severity: normal

I tried to set up ssh with public key authentication but it turned out
to be impossible without changing the permissions of my home directory.
While this is not a major obstacle, figuring out what the permissions
ought to be was less than obvious.

Turns out that chmod 2700 and 2711 ~ is okay, while anything with read
permissions for group is unacceptable. (I'm speculating a bit here
because I haven't done exhaustive testing [*].)

This bug is probably a packaging error, seeing as the owner=group
convention is somewhat specific to Debian (and Red Hat, IIRC) while
the upstream edition of SSH probably wants to continue to be paranoid
about group-readable home directories.

Troubleshooting this was hard because there is no fair warning -- it
took me a while to notice the error messages in auth.log. It would be
ideal if the error could be displayed on the terminal of the user who
is attempting to log in (I fail to see how this could open up any
major security problems).

So I'd like to see

 1) the Debian package fixed so that group ownership checks are
    ignored if the group ID is equal to the user's login ID (and/or
    the user ID is in the interval defined to be reserved for local
    users as per Debian policy)

 2) any home directory permission requirements clearly documented

 3) permission warnings to be displayed to the user who is trying to
    log in, and getting rejected because of permission problems

 4) tangentially, the behavior when permissions are wrong is a bit
    strange when it comes to prompting for a password. Specifically,
    if I have added the key with ssh-add, I will get three password
    prompts: 

    1. when the authorization agent's public key is checked and rejected,
       it will ask for the key's passphrase -- to no avail, it's not the
       lack of a passphrase which is causing the rejection

    2. falls back to using the regular identity key, same thing again
       (even if the agent was trying the identity key originally!)

    3. and then finally fall back to regular password authentication
       (which doesn't suffer from problems with home directory checks)

    See also BTS bug #157138.

That's a tall order; if you'd like me to break it up into smaller
bugs, write back and I'll see what I can do.

/* era */

[*] The only link where I can test this is a GPRS connection running
at approximately 9,600 bps. The simple command "ssh there echo moo"
takes on the order of three minutes to complete. I've run about ten of
those tests ...

-- System Information
Debian Release: 3.0
Kernel Version: Linux there.afraid.org 2.2.17 #1 Sun Jun 25 09:24:41 EST 2000 i586 unknown

Versions of the packages ssh depends on:
ii  adduser        3.47           Add and remove users and groups
ii  debconf        1.0.32         Debian configuration management system
ii  libc6          2.2.5-11.1     GNU C Library: Shared libraries and Timezone
ii  libpam-modules 0.72-35        Pluggable Authentication Modules for PAM
ii  libpam0g       0.72-35        Pluggable Authentication Modules library
ii  libssl0.9.6    0.9.6c-2.woody SSL shared libraries
ii  libwrap0       7.6-9          Wietse Venema's TCP wrappers library
ii  zlib1g         1.1.4-1        compression library - runtime


------------=_1780385702-2213429-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 163202-done) by bugs.debian.org; 2 Jun 2026 07:32:02 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.1 required=4.0 tests=BAYES_00,DKIM_SIGNED,
	DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED,
	RCVD_IN_MSPIKE_H5,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,SPF_PASS
	autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 11; hammy, 69; neutral, 33; spammy, 1.
	spammytokens:0.933-+--today hammytokens:0.000-+--H*r:posteo.de,
	0.000-+--H*RU:posteo.de, 0.000-+--Hx-spam-relays-external:posteo.de,
	0.000-+--Hx-spam-relays-external:submission, 0.000-+--H*RU:submission
Return-path: <[email protected]>
Received: from mout02.posteo.de ([185.67.36.66]:54041)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wUJbV-009HPg-1C
	for [email protected];
	Tue, 02 Jun 2026 07:32:02 +0000
Received: from submission (posteo.de [185.67.36.169]) 
	by mout02.posteo.de (Postfix) with ESMTPS id 86CBD240101
	for <[email protected]>; Tue,  2 Jun 2026 09:31:57 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=posteo.jp; s=2017;
	t=1780385517; bh=mrZ+v8HwYnqiWfSjrlB4WhyIjOkz1vbdLKHBQeSL8Cs=;
	h=MIME-Version:Date:From:To:Subject:Message-ID:Content-Type:
	 Content-Transfer-Encoding:From;
	b=AmZNavOqciB3pez31eYSp8yCp0WSwZ/6gMnHAioboNLHf2jrq2KzKfvrJMqAvcr6X
	 Tl+Nc5X2hdZ60eznjLdSx0wp4Qd3PwpX5+4AnFFIRi2nANLauyxkhN8z7NoaZeZAMJ
	 EAIIWp66W3OV+1IzHaKwN2Kh64eNPOOVnk9JuDxr1BVdmD7O2QOwtXpBHpQ7ZN9wnl
	 OdWEf8gjPr5SZoxEwzfic12vy2U5LHup9Bmp8tOqv1BZ21PJsjuZOA0tmIwb7oAzBE
	 RYiYpbfVjyYjxnRmHcJWlR1WjVoaFmyCV8C2EQWT8fqobpkJAE3rbtkkvnGx2gGb58
	 EIuSdOG6Tc2Sg==
Received: from customer (localhost [127.0.0.1])
	by submission (posteo.de) with ESMTPSA id 4gV2b11rQgz9rxM
	for <[email protected]>; Tue,  2 Jun 2026 09:31:57 +0200 (CEST)
MIME-Version: 1.0
Date: Tue, 02 Jun 2026 07:31:57 +0000
From: [email protected]
To: [email protected]
Subject: explained and to broad
Message-ID: <[email protected]>
Content-Type: text/plain; charset=US-ASCII;
 format=flowed
Content-Transfer-Encoding: 7bit

Hello era,
thank you for this detailed report and analysis.

The report is quite old and I can say that the behavior you described is 
today better documented (see StrictModes for example). It is intended.

Also your report mix up several issues and feature requests. Please 
check the latest version of SSH and feel free to open fresh tickets, but 
only one per issue/feature.

Regards,
Christian
------------=_1780385702-2213429-0--