Subject: Re: pam, ssh, and pam_ssh
To: None <current-users@netbsd.org>
From: Christos Zoulas <christos@tac.gw.com>
List: current-users
Date: 03/13/2005 19:42:44
In article <Pine.LNX.4.62.0503140112190.503@Psilocybe.Update.UU.SE>,
Johnny Billquist  <bqt@Update.UU.SE> wrote:
>On Sun, 13 Mar 2005, Manuel Bouyer wrote:
>
>> On Sun, Mar 13, 2005 at 06:33:18PM +0000, dieter wrote:
>>>
>>> I think either
>>> 1) pam_ssh.so should be commented out in /etc/pam.d/sshd
>>> or
>>> 2) a warning should be added to UPDATING that the behaviour of sshd is
>>> changed.
>>>
>>> Suddenly, identities in ~/.ssh work in 2 directions; not only to login
>>> some place else, but also to authenticate from remote on the local
>>> machine, regardless the contents of authorized_keys.
>>
>> I, too, think this is bad.
>
>This is not just bad, this is bloody serious. How the f*ck did that one 
>pass by?

Why is everyone jumping the gun? I just tried it and it works fine for
me. Can someone explain what the problem is? I commented out all my
authorized keys entries and sshd did not let me in anymore.

christos