Rhosts Auth Issues with OpenSSH 2.9p1 on Solaris 2.7

Carson Gaspar carson at taltos.org
Fri May 4 19:03:21 EST 2001


By default, ssh is not installed setuid root. Currently, you need to 
install it setuid root or it disables rhosts auth.

Of course, rhosts auth is a terrible idea. Are you _sure_ you mean rhosts 
auth, or do you mean RSARhosts/Hostbasedauth? These currently _also_ 
require that ssh be setuid root, but have far more security.

-- 
Carson





More information about the openssh-unix-dev mailing list