Openembedded Core Discussions
 help / color / mirror / Atom feed
From: Mark Hatle <mark.hatle@windriver.com>
To: <openembedded-core@lists.openembedded.org>
Subject: Re: [PATCHv2] openssh: allow login with empty password
Date: Mon, 14 Oct 2013 08:46:46 -0500	[thread overview]
Message-ID: <525BF5C6.7000302@windriver.com> (raw)
In-Reply-To: <F5284B34-0CDB-4F68-93B1-E748158FF690@dominion.thruhere.net>

On 10/14/13 6:09 AM, Koen Kooi wrote:
>
> Op 14 okt. 2013, om 12:37 heeft Paul Eggleton <paul.eggleton@linux.intel.com> het volgende geschreven:
>
>> On Monday 14 October 2013 12:09:37 Koen Kooi wrote:
>>> Currently both PAM and dropbear allow logins with empty passwords, but
>>> openssh doesn't. This commit changes the default in openssh to allow
>>> empty password logins.
>>>
>>> This should be changed to be a global config option in the long run.
>>>
>>> Signed-off-by: Koen Kooi <koen@dominion.thruhere.net>
>>> ---
>>> meta/recipes-connectivity/openssh/openssh-6.2p2/sshd_config | 2 +-
>>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/meta/recipes-connectivity/openssh/openssh-6.2p2/sshd_config
>>> b/meta/recipes-connectivity/openssh/openssh-6.2p2/sshd_config index
>>> 4f9b626..175e8f3 100644
>>> --- a/meta/recipes-connectivity/openssh/openssh-6.2p2/sshd_config
>>> +++ b/meta/recipes-connectivity/openssh/openssh-6.2p2/sshd_config
>>> @@ -59,7 +59,7 @@ Protocol 2
>>>
>>> # To disable tunneled clear text passwords, change to no here!
>>> #PasswordAuthentication yes
>>> -#PermitEmptyPasswords no
>>> +PermitEmptyPasswords yes
>>>
>>> # Change to no to disable s/key passwords
>>> #ChallengeResponseAuthentication yes
>>
>> We do already have logic in image.bbclass to set this based upon debug-tweaks
>> being in IMAGE_FEATURES; is that not working for you?
>
> I haven't tried that, but that still doesn't fix the inconsistency issues and presents problems during package upgrades.

If the behavior is inconsistent, then the fix should be to PAM, dropbear and the 
debug-tweaks.  (I'm really wondering if this behavior should be able to be run 
w/o the rest of the debug-tweaks.)

But the default, for security purposes, should be no root login.

--Mark

> regards,
>
> Koen
> _______________________________________________
> Openembedded-core mailing list
> Openembedded-core@lists.openembedded.org
> http://lists.openembedded.org/mailman/listinfo/openembedded-core
>



      parent reply	other threads:[~2013-10-14 13:46 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-10-14 10:09 [PATCHv2] openssh: allow login with empty password Koen Kooi
2013-10-14 10:37 ` Paul Eggleton
2013-10-14 11:09   ` Koen Kooi
2013-10-14 11:27     ` Paul Eggleton
2013-10-14 13:46     ` Mark Hatle [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=525BF5C6.7000302@windriver.com \
    --to=mark.hatle@windriver.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox