- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Disable root login with ssh?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:16 AM
02-14-2002 07:16 AM
Disable root login with ssh?
PermitRootLogin yes
...so one should be able to login as root to both, no?
But then /etc/securetty only has the line
CONSOLE
Are there other files that I need to check to find out why one is properly locked down but the other isn't???
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:18 AM
02-14-2002 07:18 AM
Re: Disable root login with ssh?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:19 AM
02-14-2002 07:19 AM
Re: Disable root login with ssh?
/etc/securetty only affects items such as rlogin and telnet, ssh is not affected. The /etc/sshd_config the PermitRootLogin option should be no if you don't want root to login. Once that change is made, then kill -HUP `cat /var/run/sshd.pid` and you should be good.
GL,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:22 AM
02-14-2002 07:22 AM
Re: Disable root login with ssh?
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:27 AM
02-14-2002 07:27 AM
Re: Disable root login with ssh?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:32 AM
02-14-2002 07:32 AM
Re: Disable root login with ssh?
Looking forward to your ssh -v output.
GL,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 07:49 AM
02-14-2002 07:49 AM
Re: Disable root login with ssh?
root@ovmngr10 $ ssh -v -l root ovmngr3
debug: hostname is 'ovmngr3'.
debug: Unable to open //.ssh2/ssh2_config
debug: connecting to ovmngr3...
debug: entering event loop
debug: ssh_client_wrap: creating transport protocol
debug: SshAuthMethodClient/sshauthmethodc.c:119: Added "publickey" to usable methods.
debug: SshAuthMethodClient/sshauthmethodc.c:119: Added "password" to usable methods.
debug: Ssh2Client/sshclient.c:1142: creating userauth protocol
debug: Ssh2Common/sshcommon.c:544: local ip = 145.26.100.103, local port = 56889
debug: Ssh2Common/sshcommon.c:546: remote ip = 145.26.100.101, remote port = 22
debug: SshConnection/sshconn.c:1866: Wrapping...
debug: Ssh2Transport/trcommon.c:599: Remote version: SSH-1.99-2.4.0 F-SECURE SSH
debug: Ssh2Transport/trcommon.c:1124: c_to_s: cipher 3des-cbc, mac hmac-sha1, compression none
debug: Ssh2Transport/trcommon.c:1127: s_to_c: cipher 3des-cbc, mac hmac-sha1, compression none
debug: Ssh2Client/sshclient.c:406: Host key found from database.
debug: Ssh2Common/sshcommon.c:348: Received SSH_CROSS_STARTUP packet from connection protocol.
debug: Ssh2Common/sshcommon.c:398: Received SSH_CROSS_ALGORITHMS packet from connection protocol.
debug: Ssh2AuthPubKeyClient/authc-pubkey.c:777: adding keyfile "//.ssh2/id_dsa_1024_a" to candidates
debug: Ssh2AuthPubKeyClient/authc-pubkey.c:777: adding keyfile "//.ssh2/id_dsa_1024_b" to candidates
debug: Ssh2AuthClient/sshauthc.c:308: Method 'publickey' disabled.
debug: Ssh2AuthPasswdClient/authc-passwd.c:95: Starting password query...
root's password:
debug: Ssh2AuthPasswdClient/authc-passwd.c:95: Starting password query...
root's password:
As you can see it didn't accept the password that I supplied (which was correct).
On the other machine it's the same except I can log in as root.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 08:09 AM
02-14-2002 08:09 AM
Re: Disable root login with ssh?
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 08:24 AM
02-14-2002 08:24 AM
Re: Disable root login with ssh?
On the box I can get into, I set the PermitRootLogins to no in the sshd_config, logged out and can still log in as root!!! Surely I'm missing the plot here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 08:28 AM
02-14-2002 08:28 AM
Re: Disable root login with ssh?
On the box you can get into, is there a ~root/.shosts file or ~root/.ssh2/authorized_keys file? These things could possibly be bypassing things. Also, what does the IgnoreRootRhosts option say in you /etc/sshd_config file.
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-14-2002 12:06 PM
02-14-2002 12:06 PM
Re: Disable root login with ssh?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-15-2002 02:22 AM
02-15-2002 02:22 AM
Re: Disable root login with ssh?
There is no .shosts file and the IgnoreRhosts in sshd_config is set to no.
Also there is no /.ssh2/authorized_keys file.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-15-2002 06:30 AM
02-15-2002 06:30 AM
Re: Disable root login with ssh?
Still willing to try and resolve this thing.
C