<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I enable ssh root login without allowing telnet root login in Operating System - Tru64 Unix</title>
    <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731345#M6058</link>
    <description>I can add ptys entry on /etc/securettys but this allows ssh and telnet to login as root. &lt;BR /&gt;&lt;BR /&gt;I also tried to set PermitRootLogin to yes on /usr/local/etc/sshd_config but I'm still not able to ssh as root. I have tried to restart sshd after changing PermitRootLogin to yes but it does not help.&lt;BR /&gt;&lt;BR /&gt;Below verifies that I am using the right config file for sshd. &lt;BR /&gt;&lt;BR /&gt;--&amp;gt; /usr/local/sbin/sshd -?        &lt;BR /&gt;sshd: illegal option -- ?&lt;BR /&gt;sshd version OpenSSH_3.7.1p2&lt;BR /&gt;Usage: sshd [options]&lt;BR /&gt;Options:&lt;BR /&gt;  -f file    Configuration file (default /usr/local/etc/sshd_config)&lt;BR /&gt;&lt;BR /&gt;I got the following error when connecting through ssh as root&lt;BR /&gt;&lt;BR /&gt;phxwa11# ssh adtdb031n1&lt;BR /&gt;Not authorized for terminal access -- see System Administrator.&lt;BR /&gt;&lt;BR /&gt;Connection to adtdb031n1 closed.&lt;BR /&gt;&lt;BR /&gt;/var/adm/syslog.dated/current/auth.log shows the following&lt;BR /&gt;&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979747]: Accepted publickey for root from 10.40.&lt;BR /&gt;248.36 port 45858 ssh2&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979774]: ROOT LOGIN REFUSED /dev/pts/7&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979774]: fatal: Couldn't establish session for r&lt;BR /&gt;oot from phxwa11.firsthealth.com</description>
    <pubDate>Tue, 14 Feb 2006 14:32:33 GMT</pubDate>
    <dc:creator>Hong Liao_1</dc:creator>
    <dc:date>2006-02-14T14:32:33Z</dc:date>
    <item>
      <title>How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731345#M6058</link>
      <description>I can add ptys entry on /etc/securettys but this allows ssh and telnet to login as root. &lt;BR /&gt;&lt;BR /&gt;I also tried to set PermitRootLogin to yes on /usr/local/etc/sshd_config but I'm still not able to ssh as root. I have tried to restart sshd after changing PermitRootLogin to yes but it does not help.&lt;BR /&gt;&lt;BR /&gt;Below verifies that I am using the right config file for sshd. &lt;BR /&gt;&lt;BR /&gt;--&amp;gt; /usr/local/sbin/sshd -?        &lt;BR /&gt;sshd: illegal option -- ?&lt;BR /&gt;sshd version OpenSSH_3.7.1p2&lt;BR /&gt;Usage: sshd [options]&lt;BR /&gt;Options:&lt;BR /&gt;  -f file    Configuration file (default /usr/local/etc/sshd_config)&lt;BR /&gt;&lt;BR /&gt;I got the following error when connecting through ssh as root&lt;BR /&gt;&lt;BR /&gt;phxwa11# ssh adtdb031n1&lt;BR /&gt;Not authorized for terminal access -- see System Administrator.&lt;BR /&gt;&lt;BR /&gt;Connection to adtdb031n1 closed.&lt;BR /&gt;&lt;BR /&gt;/var/adm/syslog.dated/current/auth.log shows the following&lt;BR /&gt;&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979747]: Accepted publickey for root from 10.40.&lt;BR /&gt;248.36 port 45858 ssh2&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979774]: ROOT LOGIN REFUSED /dev/pts/7&lt;BR /&gt;Feb 14 12:24:38 adtdb031n1 sshd[979774]: fatal: Couldn't establish session for r&lt;BR /&gt;oot from phxwa11.firsthealth.com</description>
      <pubDate>Tue, 14 Feb 2006 14:32:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731345#M6058</guid>
      <dc:creator>Hong Liao_1</dc:creator>
      <dc:date>2006-02-14T14:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731346#M6059</link>
      <description>Root login is not recommended either by telnet or ssh.&lt;BR /&gt;&lt;BR /&gt;To disable root access by telnet, remove the ptys entry from /etc/securettys. You should also disable the telnet service from /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;The configuration file for SSH is /etc/ssh2/sshd2_config. There is where you need to enable PermitRootLogin. As far I know, the securettys file does not have influence in root access through SSH (I don't have ptys on my system).</description>
      <pubDate>Tue, 14 Feb 2006 14:53:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731346#M6059</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-02-14T14:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731347#M6060</link>
      <description>Both  /usr/local/etc/sshd_config and /etc/ssh2/sshd2_config PermitRootLogin  are set to Yes. &lt;BR /&gt;&lt;BR /&gt;ptys is not currently added on /etc/securettys because we don't want telnet to login directly as root. We can disable telnet later by removing it entry from /etc/inetd.conf. Right now we only need to allow ssh to login as root. Currently we were able to run a command through ssh as root without any issue and ssh does not prompt for password since we configure ssh to allow root without password.  &lt;BR /&gt;&lt;BR /&gt;Thanks for the help.</description>
      <pubDate>Tue, 14 Feb 2006 15:24:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731347#M6060</guid>
      <dc:creator>Hong Liao_1</dc:creator>
      <dc:date>2006-02-14T15:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731348#M6061</link>
      <description>That's good!.&lt;BR /&gt;&lt;BR /&gt;Please see also:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/helptips.do?#28" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/helptips.do?#28&lt;/A&gt;</description>
      <pubDate>Tue, 14 Feb 2006 16:03:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731348#M6061</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-02-14T16:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731349#M6062</link>
      <description>Hi all, &lt;BR /&gt;actually I have the same problem, but don't know how to solve it:&lt;BR /&gt;SRV2 has enhanced security installed&lt;BR /&gt;SRV1 has no enhanced security.&lt;BR /&gt;&lt;BR /&gt;direct root login via ssh on SRV1 is ok&lt;BR /&gt;direct root login via ssh on SRV2 is restricted even though sshd is set to "yes"&lt;BR /&gt;&lt;BR /&gt;So the question still stands, how to enable ssh root direct login without editing securettys? I believe that there is some trick with enhaned security, but can't figure it out.&lt;BR /&gt;&lt;BR /&gt;Any idea ?&lt;BR /&gt;&lt;BR /&gt;MGMCON&amp;gt; ssh -q root@SRV1&lt;BR /&gt;Last login: Wed Feb 15 09:09:52 CET 2006 from MGMCON&lt;BR /&gt;...&lt;BR /&gt;&lt;BR /&gt;You have new mail.&lt;BR /&gt;SRV1 :root# tail /etc/securettys&lt;BR /&gt;...&lt;BR /&gt;#  &lt;DEVICE name=""&gt;&lt;BR /&gt;/dev/console&lt;BR /&gt;local:0&lt;BR /&gt;:0&lt;BR /&gt;SRV1 :root#&lt;BR /&gt;SRV1 :root# grep -i permitroot /etc/ssh2/sshd2_config&lt;BR /&gt;        PermitRootLogin                 yes&lt;BR /&gt;#       PermitRootLogin                 nopwd&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;MGMCON&amp;gt; ssh -q root@SRV2&lt;BR /&gt;Not authorized for terminal access -- see System Administrator.&lt;BR /&gt;&lt;BR /&gt;MGMCON&amp;gt; ssh SRV2&lt;BR /&gt;Authentication successful.&lt;BR /&gt;Last   successful login for aco: Wed Feb 15 09:01:49 CET 2006 from MGMCON&lt;BR /&gt;Last unsuccessful login for aco: NEVER&lt;BR /&gt;&lt;BR /&gt;Compaq Tru64 UNIX V5.1A (Rev. 1885); Sat Sep 13 19:37:43 CEST 2003&lt;BR /&gt;...&lt;BR /&gt;No mail.&lt;BR /&gt;$ su -&lt;BR /&gt;Password:&lt;BR /&gt;SRV2 :root# tail -n -3 /etc/securettys&lt;BR /&gt;/dev/console&lt;BR /&gt;local:0&lt;BR /&gt;:0&lt;BR /&gt;SRV2 :root# grep -i permitroot /etc/ssh2/sshd2_config&lt;BR /&gt;        PermitRootLogin                 yes&lt;BR /&gt;#       PermitRootLogin                 nopwd&lt;BR /&gt;SRV2 :root#&lt;BR /&gt;&lt;BR /&gt;P.S. if I put ptys in securettys on SRV2 then it works fine...&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/DEVICE&gt;</description>
      <pubDate>Wed, 15 Feb 2006 03:24:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731349#M6062</guid>
      <dc:creator>Aco Blazeski</dc:creator>
      <dc:date>2006-02-15T03:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable ssh root login without allowing telnet root login</title>
      <link>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731350#M6063</link>
      <description>An authorized user list can be created for a particular terminal. If such a list exists, your user name must appear in the list or you cannot log in at that terminal. In this case, the system displays the following message:&lt;BR /&gt;&lt;BR /&gt;Not authorized for terminal access--see System Administrator&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This is not a SSH restriction, this is an ENHANCED SECURITY restriction.</description>
      <pubDate>Wed, 15 Feb 2006 07:40:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-tru64-unix/how-do-i-enable-ssh-root-login-without-allowing-telnet-root/m-p/3731350#M6063</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-02-15T07:40:14Z</dc:date>
    </item>
  </channel>
</rss>

