locked account accessable via pubkey auth

Dost, Alexander Alexander.Dost at drkw.com
Tue Jan 29 22:56:55 EST 2002


maybe this is a silly question ;-) But why is it possible to login on a
machine with a locked account (passwd -l ) via pubkey-authentication
(authorized_keys) ?
I use OpenSSH3.01p1on Solaris8 with PAM support so I thought this should not
happen.

If this is the normal behaviour and built in intentionally what would be the
easiest way to lock an account without deleting the users authorized_keys ?
If not, what output do you need to verify the problem ?

Alex




More information about the openssh-unix-dev mailing list