Bug 22 - VOLUNTEER:Addition of user based control of authentication methods
Summary: VOLUNTEER:Addition of user based control of authentication methods
Status: CLOSED DUPLICATE of bug 1180
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: sshd (show other bugs)
Version: -current
Hardware: All Other
: P2 enhancement
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
: 767 (view as bug list)
Depends on:
Blocks:
 
Reported: 2001-11-22 04:20 AEDT by reskusic
Modified: 2008-04-04 09:54 AEDT (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description reskusic 2001-11-22 04:20:52 AEDT
I added a few features to openssh for my local use that I'd like to
submit back to the main project.  I basically added access control
lists to control who would be allowed public key authentication.  I
added four config file entries for the server:           

PubkeyAllowUsers
PubkeyDenyUsers
PubkeyAllowGroups
PubkeyDenyGroups

These follow the same sematics as the already existing entries for
allowing logins.  So far I have this implemented for SSH2 pubkey auth,
but I coded it to make adding corresponding entries for any auth
method easy.  I'd be happy to do so if this was desired.
I'm not sure if there is any interest this functionality, but I've
been wanting it for a while  In particular, it's helpful to allow
pubkey auth for trusted users and trusted systems, while not allowing
the other 10000 users to make it into another .rhosts

I have working code built off the portable release.
Comment 1 Damien Miller 2005-04-21 18:10:28 AEST
*** Bug 767 has been marked as a duplicate of this bug. ***
Comment 2 Darren Tucker 2006-10-07 12:26:05 AEST
We have implemented a general mechanism to enable directives based on certain criteria, including user and group.  It doesn't support authentications yet, but it's planned for the next release.  With it, you would enable, say, pubkey authentication only for certain users thusly:

PubkeyAuthentication no
Match User foo,bar
    PubkeyAuthentication yes

*** This bug has been marked as a duplicate of bug 1180 ***
Comment 3 Damien Miller 2008-04-04 09:54:29 AEDT
Close resolved bugs after release.