Bug 1226 - sftp-server does not respect rlogin = false
Summary: sftp-server does not respect rlogin = false
Status: CLOSED INVALID
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sftp-server (show other bugs)
Version: 4.3p2
Hardware: PPC AIX
: P2 normal
Assignee: Assigned to nobody
URL:
Keywords:
: 1227 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-09-13 21:55 AEST by Cris B
Modified: 2006-10-07 11:45 AEST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cris B 2006-09-13 21:55:10 AEST
using the packages from http://sf.net/projects/openssh-aix

have set a user 'appa' to be rlogin=false in /etc/security/users

when I 'ssh appa@gromit':

appa@gromit's password:
Received disconnect from 158.234.7.207: 2: Remote login for account appa is not
allowed.

when i 'scp *.txt appa@gromit:~':

appa@gromit's password:
Received disconnect from 158.234.7.207: 2: Remote login for account appa is not
allowed.
lost connection

so all good so far, but when I 'sftp appa@gromit':

Connecting to gromit...
appa@gromit's password:
sftp>

i am allowed to log in!!!!! this happens only on AIX5.3. On AIX5.2 (same  user setup) I get:

Connecting to fenris...
appa@fenris's password:
Permission denied, please try again.
Comment 1 Darren Tucker 2006-09-13 22:16:54 AEST
(In reply to comment #0)
> using the packages from http://sf.net/projects/openssh-aix

We can't help you, you'll have to follow this up with them.  Last time I checked those packages a) contained modifications b) to which there's no source and c) are version 4.1p1 (not 4.3p1, which is what this bug is against).

If you are able to reproduce this with the vanilla source from openssh.com then we may be able to help you (but the rlogin check is in allowed_user()  which is always called, so I doubt you'll see it).
Comment 2 Darren Tucker 2006-09-13 22:18:45 AEST
*** Bug 1227 has been marked as a duplicate of this bug. ***
Comment 3 Darren Tucker 2006-10-03 19:09:24 AEST
One other thing: the disconnect message if charateristic of what PAM sends so you may be seeing a difference between AIX 5.2 and 5.3 because of the UsePAM setting in sshd_config and/or the sshd PAM configuration.

Anyway, as I said we are not able to help you with anyone else's binaries so I'm closing this bug.  Please feel free to reopen if you can reproduce it with the software from openssh.com.
Comment 4 Darren Tucker 2006-10-07 11:45:50 AEST
Change all RESOLVED bug to CLOSED with the exception of the ones fixed post-4.4.