看板 FB_security 關於我們 聯絡資訊
On Nov 15, 2011, at 3:12 PM, Dag-Erling Sm=F8rgrav wrote: > Guy Helmer <guy.helmer@palisadesystems.com> writes: >> I have a shell user who is able to login to his accounts via sshd on >> FreeBSD 8.2 using any password. The user had a .ssh/id_rsa and >> .ssh/id_rsa.pub key pair without a password but nullok was not >> specified, so I think this should be considered a bug. >=20 > It turns out that this goes all the way to OpenSSL, which ignores the > passphrase if the key is not encrypted. The only solution I can think > of - more of a workaround, really - is to first try to load the key = with > an empty passphrase, and skip the key if that worked. See the = attached > (untested) patch. >=20 > A more advanced patch would load all keys but require at least one of > them to have a passphrase. >=20 > DES > --=20 > Dag-Erling Sm=F8rgrav - des@des.no >=20 > <pam_ssh_nullok.diff> Yes, that patch applied OK to the 8.2 test machine and resolved the = issue with the unencrypted id_rsa private key. I didn't know of any = other way to check the key either - nothing jumped out at me from the = OpenSSL API documentation. Thanks for the quick turnaround, Guy -------- This message has been scanned by ComplianceSafe, powered by Palisade's PacketSure. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"