OpenSSH
[Top] [All Lists]

Re: Verbose messaging about why public key auth was rejected

To: Ryan Findley <ryan@neomindstudio.com>
Subject: Re: Verbose messaging about why public key auth was rejected
From: Damien Miller <djm@mindrot.org>
Date: Sun, 4 Feb 2007 09:22:49 +1100 (EST)
Cc: openssh-unix-dev@mindrot.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: openssh-unix-dev-list1@securepoint.com
Delivered-to: openssh-unix-dev-tmda@mindrot.org
Delivered-to: openssh-unix-dev@mindrot.org
In-reply-to: <3109E259-4D89-4A8D-A218-A10A5D16CD92@neomindstudio.com>
List-archive: <http://lists.mindrot.org/pipermail/openssh-unix-dev>
List-help: <mailto:openssh-unix-dev-request@mindrot.org?subject=help>
List-id: Development of portable OpenSSH <openssh-unix-dev.mindrot.org>
List-post: <mailto:openssh-unix-dev@mindrot.org>
List-subscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=subscribe>
List-unsubscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=unsubscribe>
References: <3109E259-4D89-4A8D-A218-A10A5D16CD92@neomindstudio.com>
Sender: openssh-unix-dev-bounces+openssh-unix-dev-list1=securepoint.com@mindrot.org
On Tue, 30 Jan 2007, Ryan Findley wrote:

> My question: is there a way to have ssh and/or sshd tell you WHY a  
> public key is being rejected (specifically the permissions thing)?
> If so, can someone point me at a good document? I'm using OpenSSH  
> 3.9p1 under RHEL4 (at the moment) and can upgrade if it's in a newer  
> version.
> If not, would the OpenSSH team consider adding this feature? I'm  
> betting I could probably manage the changes necessary, and submit a  
> patch...

I don't think we want to tell the client exactly what is wrong
wrt authorized_keys permissions. How do you know the client is not
evil before you tell them that their authorized_keys is word-writable?

-d
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

<Prev in Thread] Current Thread [Next in Thread>