Bug 1128 - Configuration keyword "ShostsFile (or RhostsFile)" does not exist
Summary: Configuration keyword "ShostsFile (or RhostsFile)" does not exist
Status: NEW
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sshd (show other bugs)
Version: 4.2p1
Hardware: All All
: P3 enhancement
Assignee: Assigned to nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-01 19:00 AEDT by SASAJIMA Toshihiro
Modified: 2005-12-01 19:35 AEDT (History)
0 users

See Also:


Attachments
this patch appends configuration keyword "ShostsFile" (10.38 KB, patch)
2005-12-01 19:13 AEDT, SASAJIMA Toshihiro
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description SASAJIMA Toshihiro 2005-12-01 19:00:04 AEDT
Configuration keyword "AuthorizedKeyFile" is very useful.
If your sshd permits PubkeyAuthentication and you want to that only root user edits all authorized_keys files in the host, you can use "AuthorizedKeyFile" to put the file into system configuration directory.

If your sshd permits HostbasedAuthentication and you want to that only root user edits all .shosts/.rhosts files, you will need configuration keyword "ShostsFile".
Comment 1 Damien Miller 2005-12-01 19:03:54 AEDT
If you want deny user control of HostbasedAuthentication, then you can enter users in /etc/shosts.equiv and set IgnoreRhosts=yes in sshd_config

Does that solve your problem?
Comment 2 SASAJIMA Toshihiro 2005-12-01 19:13:12 AEDT
Created attachment 1033 [details]
this patch appends configuration keyword "ShostsFile"

This patch works in my Solaris8 box.
Comment 3 SASAJIMA Toshihiro 2005-12-01 19:35:39 AEDT
(In reply to comment #1)
> If you want deny user control of HostbasedAuthentication, then you can enter
> users in /etc/shosts.equiv and set IgnoreRhosts=yes in sshd_config
> 
> Does that solve your problem?
> 

No, hosts.equiv only solves following: 

   foo@localhost -> foo@remotehost

But I assume following:

   foo@localhost -> bar@remotehost