Subject: Re: Regarding the use of pam_ssh
To: Jason Thorpe <thorpej@shagadelic.org>
From: John Nemeth <jnemeth@victoria.tc.ca>
List: tech-security
Date: 02/27/2005 12:05:02
On Jul 20,  6:30am, Jason Thorpe wrote:
} On Feb 27, 2005, at 11:05 AM, John Nemeth wrote:
} 
} >      Based on this, pppd should be fine, since it would primarily be
} > used for modems that are directly attached to the system (modems
} > attached to terminal servers would usually use RADIUS).  How about
} > racoon?  I don't know if the passwords it sends are sent over an
} > encrypted channel.  Since login would be used primarily by getty runing
} > on the console or direct attached serial terminals/modems how about
} > it?
} 
} racoon should probably be fine -- check with manu.  pppd should also be 
} fine.

     Emmanuel, are you reading this?

} login -- yah, I guess that's true, although it's also possible to run 
} login(1) manually after one has telnet'd into a system.

     It's possible to do all sorts of silly things after telnet'ing
into a system.  There is a limit to what we can do to protect people
from their own lack of knowledge.

}-- End of excerpt from Jason Thorpe