Subject: Re: PAM vulnerability in portable OpenSSH
To: Damien Miller <djm@mindrot.org>
From: Stephen Smoogen <smoogen@lanl.gov>
List: current-users
Date: 09/24/2003 10:41:09
On Tue, 2003-09-23 at 16:08, Damien Miller wrote:
> > Interesting quote:
> > 
> > "Due to complexity, inconsistencies in the specification and differences
> > between vendors' PAM implementations we recommend that PAM be left disabled
> > in sshd_config unless there is a need for its use. Sites only using public
> > key or simple password authentication usually have little need to enable PAM
> > support."
> > 
> > Slander? Don't think so.
> 
> It is only slander if it is false. Let's look at the charges:
> 

I agee with all the charges.. but I would like to know if in your
opinion it is fixable or should be looked at from ground 0. [Not asking
OpenBSD/SSH to fix it.. you have enough on your plate for volunteers.] 


-- 
Stephen John Smoogen		smoogen@lanl.gov
Los Alamos National Labrador  CCN-5 Sched 5/40  PH: 4-0645 (note new #)
Ta-03 SM-1498 MailStop B255 DP 10S  Los Alamos, NM 87545
-- So shines a good deed in a weary world. = Willy Wonka --