patch - forceshell

Damien Miller djm at mindrot.org
Sat Oct 6 08:13:41 EST 2001


On Fri, 5 Oct 2001, Don Mahurin wrote:

> Damien Miller wrote:
> 
> > > I don't want any magic.  With a shell= auth param, the client side
> > > users need to know nothing, and can use unmodified ssh clients.
> >
> > I don't see the need for modified ssh clients and I can see why
> > SSH_ORIGINAL_COMMAND is no help?
> 
> The patch was a simple server side change. Ordinary ssh clients can
> be used with this.

Ordinary ssh clients can be used without the patch.

> You are proposing that instead, the shell ( or wrapper ) must be
> modified to understand the env var.

I am proposing a wrapper.

> But this reliance on SSH_ORIGINAL_COMMAND is somewhat sloppy       .
> and could break with an ssh change (Imagine if ssh's problem of    .
> unquoting commands was fixed)                                      .

What problem?

-d

-- 
| Damien Miller <djm at mindrot.org> \ ``E-mail attachments are the poor man's 
| http://www.mindrot.org          /   distributed filesystem'' - Dan Geer




More information about the openssh-unix-dev mailing list