Re: Elimination of ssh chatting - Possible solution

Michael Shigorin <[email protected]>
Newsgroups gmane.linux.terminal-server.devel
Message-ID <[email protected]>
On Mon, Mar 17, 2008 at 11:44:53AM -0500, Scott Balneaves wrote:
> Here's what would be really cool.
> The greeter, per se, would disappear.  We'd have 3 small
> programs running on the "greeter" screen:

Reasonable (given ssh in the first place).

> "But what happens if the password expires, Scott?"
> 2) An ability to allow ssh to do X forwarding even when a
> password is expired.  Currently, if your password's expired, X
> forwarding doesn't work.

Well, you try to force stateful operation when it should be
stateless (before login, user is anonymous; after login, they're
granted credentials).

Could it be reasonable to use one connection (presumably by
a sort of pre-generated key) for initial X forwarding and 
a _different_ one when user got authenticated?

(NB: I really don't know exactly how things are done currently,
although we're moving to 5.1 as I write this message -- should
ask the colleague and go read the scripts...)

> What this requires is 2 things, both modifications to sshd:
> 1) We'll need a new option to sshd_config, call it
>    PamPasswordProgram %s
>    or similar, to allow us to specify a program other than passwd for
>    handling expired passwords.  And:

IMHO this has a chance, given *-ssh-askpass existence...

> 2) An option like:
>    ForwardXWithExpiredPassword (y/n)
>    Which would allow us to control the X forwarding with expired passwords.
>    Default behaviour would be as it is now, as "n"

...and this has none.

> So, the question becomes, how do we go about this.  My first
> instinct would be to try to approach one of the ssh authors,
> and see if we could make this fly.

I'm afraid another one might see if he could make *you* fly :(
Judging by personal experience, Theo is fine gentleman.

> What do people think?

I can ask our openssh maintainer, maybe he'd offer some advice.
Bet that (2) would get some flak though...

PS: is it me only or does NX look like something already there
regarding encrypted communications too?

-- 
 ---- WBR, Michael Shigorin <mike-u2l5PoMzF/[email protected]>
  ------ Linux.Kiev http://www.linux.kiev.ua/

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_____________________________________________________________________
Ltsp-developer mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-developer
For additional LTSP help,   try #ltsp channel on irc.freenode.net
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.