public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] locking user accounts doesn't really lock them.
@ 2003-10-31 21:27 Kurt Lieber
  2003-10-31 21:55 ` Kevyn Shortell
  0 siblings, 1 reply; 6+ messages in thread
From: Kurt Lieber @ 2003-10-31 21:27 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 551 bytes --]

Right now, at least on Gentoo, if you lock a user's account with passwd -l
<username>, that user is still able to access their account if they have
ssh keys set up.  This is, in my mind, a fairly big security hole.
Googling, I found an issue related to the Solaris implementation of PAM[1]
that was fixed in a later version.

Does anyone know if there is a way to fix this in Gentoo and/or Linux?  (I
don't have access to any non-Gentoo linux boxen atm, so I can't say for
sure if this issue exists on other distros)  A tweak to PAM, perhaps?

--kurt

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-11-01 11:55 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-31 21:27 [gentoo-dev] locking user accounts doesn't really lock them Kurt Lieber
2003-10-31 21:55 ` Kevyn Shortell
2003-10-31 22:01   ` Kurt Lieber
2003-10-31 22:18     ` Kurt Lieber
2003-11-01  2:47       ` Lisa Seelye
2003-11-01 11:50     ` Eldad Zack

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox