Re: a GOOD idea to harden OpenSSH!

Aaron Toponce <[email protected]> Sat, 2 Apr 2011 05:57:13 -0600
Newsgroups gmane.network.openssh.general
Message-ID <[email protected]>
--h1wVxq8aeHrvhZJz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Mar 31, 2011 at 03:20:38PM -0300, Christian Grunfeld wrote:
> This will not disturb a normal human login with a couple failures but
> makes a robot to wait with a potential law.

That really isn't the job of OpenSSH, but more for PAM or some other
authentication module. Further, there is already software to prevent robots
=66rom getting into your server, such as Netfilter, TCPWrappers and
Denyhosts.

Interesting idea, but something like delaying logins really belongs
elsewhere in the system.

--
=2E o .   o . o   . . o   o . .   . o .
=2E . o   . o o   o . o   . o o   . . o
o o o   . o .   . o o   o o .   o o o

--h1wVxq8aeHrvhZJz
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: http://tinyurl.com/aarongpg

iQEcBAEBCgAGBQJNlw8ZAAoJEM55Ebf8BAiPlbsH/2ENWQcld/Eud2dZZIi+573h
vR3yswKgydGgd0C47rYncXZEMdjLC2ZXiVFvFilf8FtGr9Q6ys49FEkGZmAkDxJ9
YT+KydY580aDB8eC4s5BmAOQ+fFo8d5kuCE4QFBNaJE3ji+cu+zo/J6nYbmCLlSq
K+Ep0qqu84GfZ/qg0pPGKm6pa5EeEJRyh0UK7GCjdeMWZ9nBkPYAABbloX/tS4UB
ueHOptcHCbfESnorBJ+FzacXER5qwiLCURB3KZqeeUksYoomBZtwUPY1/fOTIZB5
87I+8M40mgkq5wOdnX9ysRS3AxWcsFFFI9cEzdXBg58pjNhwUazgmW2sXVFxm0g=
=Vvg4
-----END PGP SIGNATURE-----

--h1wVxq8aeHrvhZJz--