Re: Early heads-up: plan to remove local patches for TCP Wrappers support in sshd

Joey Kelly <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <1997012.9LfIMBbbVL@deborah>
On Friday, February 14, 2020 04:16:53 PM Ed Maste wrote:
> On Fri, 14 Feb 2020 at 15:27, Joey Kelly <[email protected]> wrote:
> > On Friday, February 14, 2020 01:18:44 PM Ed Maste wrote:
> > > Upstream OpenSSH-portable removed libwrap support in version 6.7,
> > > released in October 2014. We've maintained a patch in our tree to
> > > restore it, but it causes friction on each OpenSSH update and may
> > > introduce security vulnerabilities not present upstream. It's (past)
> > > time to remove it.
> > 
> > So color me ignorant, but how does this affect things like DenyHosts?
> 
> It's independent of denyhosts, fail2ban, blacklistd and similar. TCP
> wrappers is configured using /etc/hosts.allow and /etc/hosts.deny.

root@marsh:~ # tail -3 /etc/hosts.allow
# for denyhosts
sshd : /etc/hosts.deniedssh : deny
sshd : ALL : allow




-- 
Joey Kelly
Minister of the Gospel and Linux Consultant
http://joeykelly.net
504-239-6550
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.