Bug 70 - Allow 'authorize host' questions to be able to be answered via GUI app
Summary: Allow 'authorize host' questions to be able to be answered via GUI app
Status: CLOSED FIXED
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: ssh (show other bugs)
Version: -current
Hardware: Other Other
: P2 enhancement
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-01-16 16:19 AEDT by Bill Bumgarner
Modified: 2004-04-14 12:24 AEST (History)
1 user (show)

See Also:


Attachments
like this? (3.75 KB, patch)
2002-01-17 02:19 AEDT, Markus Friedl
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Bill Bumgarner 2002-01-16 16:19:39 AEDT
Just like ssh can ask for a password via the SSH_ASKPASS hook, it would be extremely useful if ssh would have a hook to ask for authorization of a machine key via some external command hook.

	If there isn't a valid TTY, ssh will fail if the user has never logged into a particular machine as there is no way to ask the user if it a particular machine has acceptably identified itself.
Comment 1 Damien Miller 2002-01-17 00:24:47 AEDT
I like this idea - we could probably reuse most of the askpass code to obtain
the answer (which should still IMO require the _typing_ of "yes").
Comment 2 Markus Friedl 2002-01-17 02:19:16 AEDT
Created attachment 10 [details]
like this?
Comment 3 Jim Knoble 2002-01-17 19:25:24 AEDT
It wouldn't be too difficult to massage x11-ssh-askpass
to provide a real sort of "yes-or-no" functionality, as
long as we all agree on how to tell ssh-askpass to "be
a yes-or-no dialog instead of a passphrase dialog".

Then again, xmessage works for that sort of thing already;
a shell wrapper around it would be even easier....
Comment 4 Damien Miller 2002-01-18 11:38:19 AEDT
The patch is nice and shorter too.

The "yes"/"no" response won't be visible in the SSH_ASKPASS program, but I don't
think this is a major problem. Perhaps we could arrange some standard way to
tell the askpass to echo (cmdline arg?)

CCing jmknoble@pobox.com as the author of x11-ssh-askpass
Comment 5 Damien Miller 2002-01-18 14:59:28 AEDT
oops - I failed to see that Jim was already reading this. 

I wouldn't want a click-for-accept-this-key dialog box. Forcing people to type
"yes" has a hope of making them stop and think for a second or two about the
validity of the key.
Comment 6 Damien Miller 2002-01-23 17:28:41 AEDT
Markus committed support for this a couple of days back and I merged it into
portable last night. Open a seperate bugs if there are any issues with it.
Comment 7 Damien Miller 2004-04-14 12:24:17 AEST
Mass change of RESOLVED bugs to CLOSED