Test for locked account in auth.c (bug #442).

Damien Miller djm at mindrot.org
Mon Jan 13 09:39:43 EST 2003


Kevin Steves wrote:
> i just wonder if we really want to attempt all these checks.  if you
> lock a user's password but leave the authorized_keys file permitting
> access is the account locked?  there's a split in opinion on that i
> think.

I am beginning to agree - the change is much less attractive now than 
when I merged it. This change also moves us away from the OpenBSD 
behaviour, which is something we shouldn't do.

-d





More information about the openssh-unix-dev mailing list