Re: openssh
Scot Mc Pherson <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
On Mon, 09 Dec 2002 12:24:00 -0500, Dagmar d'Surreal wrote: > On Mon, 2002-12-09 at 02:22, Rainer Peter Feller wrote: >> On Fri, 6 Dec 2002, Dagmar d'Surreal wrote: >> >> > More and more it sounds like you need to use restricted shell >> > accounts instead of allowing the users to run whatever commands they >> > want. Or better yet, since the users don't seem to be able to do >> > much of anything anyway, _disable_ their shell accounts entirely. >> > Speeds up their connection, indeed. >> >> Hm ... restricted shell ... I am afraid that's not what they want to >> have. My problem is that, on one hand, my customers (all other people >> of my institute) do not want the whole stuff too complicate. > > A restricted shell does not make things more complicated for users. > Everything looks the same to them, aside from they only get to run a > very small list of commands. > >> On the other hand, I don't want someone who got somehow into the system >> easy to screw up my network. My problem is not the "normal" user, but >> some script kiddies which got a password by installing a patched >> ssh-client on an untrusted host. > > ...then you need a restricted shell, *and* everything I mentioned in > that other post, especially the pro-police patch for gcc, and the > grsecurity patch. the largest restriction users will ntoice is not eing able to cd into another directory Scot -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message