Bug 1410 - Correct UsePAM comment in sshd_config on Mac OS X
Summary: Correct UsePAM comment in sshd_config on Mac OS X
Status: CLOSED WONTFIX
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: PAM support (show other bugs)
Version: 4.7p1
Hardware: Other Mac OS X
: P2 normal
Assignee: Assigned to nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-21 15:12 AEDT by Disco Vince Giffin
Modified: 2008-04-04 10:01 AEDT (History)
1 user (show)

See Also:


Attachments
Corrects comments in sshd_config about using PAM with OpenSSH. (976 bytes, patch)
2007-12-21 15:12 AEDT, Disco Vince Giffin
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Disco Vince Giffin 2007-12-21 15:12:56 AEDT
Created attachment 1405 [details]
Corrects comments in sshd_config about using PAM with OpenSSH.

Attached is a patch for building OpenSSH 4.7p1 on Mac OS X.

This patch corrects comments in sshd_config about using PAM with OpenSSH.
Comment 1 Darren Tucker 2007-12-29 02:56:46 AEDT
Comment on attachment 1405 [details]
Corrects comments in sshd_config about using PAM with OpenSSH.

>-# To disable tunneled clear text passwords, change to no here!
>+# To disable tunneled clear text passwords, change to no here! Also,
>+# remember to set the UsePAM setting to 'no'.
> #PasswordAuthentication yes
> #PermitEmptyPasswords no

What is the meaning of this change?  What does UsePam=no have to do with whether or
not PasswordAuthentication is enabled?

It might be referring to ChallengeResponseAuthentication which looks similar to a casual observer, but there is already text in sshd_config and sshd(8) that covers that.

>@@ -78,7 +79,10 @@
> # If you just want the PAM account and session checks to run without
> # PAM authentication, then enable this but set PasswordAuthentication
> # and ChallengeResponseAuthentication to 'no'.

>+# Also, PAM will deny null passwords by default.  If you need to allow
>+# null passwords, add the "	nullok" option to the end of the
>+# securityserver.so line in /etc/pam.d/sshd.

That is very platform specific.  I would probably be OK with adding a comment in platform-neutral language to the UsePAM section that mentions this.

>-#UsePAM no
>+#UsePAM yes

That is documenting a local change, and I don't think we want to change the default.
Comment 2 Damien Miller 2008-01-20 06:46:29 AEDT
We won't apply this diff - sshd_config isn't the place for a description of how to configure PAM.
Comment 3 Damien Miller 2008-04-04 10:01:37 AEDT
Close resolved bugs after release.