Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

[SOLVED] sshd_config questions

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
3 posts • Page 1 of 1
Author
Message
Kvetch
Guru
Guru
User avatar
Posts: 318
Joined: Thu Apr 29, 2004 1:42 am
Location: /dev/null, VA
Contact:
Contact Kvetch
Website

[SOLVED] sshd_config questions

  • Quote

Post by Kvetch » Fri Jan 16, 2009 6:40 pm

I have a couple questions regarding my openssh installation. This is a new machine so I am hardening my default settings. My installation was compiled with the following use flags

Code: Select all

USE="X* kerberos* ldap* pam tcpd -X509 -hpn -libedit (-selinux) -skey -smartcard -static (-chroot%)"
I am not using Kerberos nor GSSAPI so I want to disable them in the conf

Code: Select all

KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no

# GSSAPI options
GSSAPIAuthentication no
but when I restart sshd I get an error stating

Code: Select all

/etc/ssh/sshd_config line 69: Unsupported option KerberosAuthentication
/etc/ssh/sshd_config line 75: Unsupported option GSSAPIAuthentication 
Why are these unsupported (especially kerberos since it was compiled to use it)? Do I not have to uncomment and set to no then?

Also http://www.gentoo.org/proj/en/infrastru ... ig-ssh.xml mentions an option called

Code: Select all

PAMAuthenticationViaKbdInt no
Has this option been removed?

thanks
Last edited by Kvetch on Mon Jan 19, 2009 2:54 am, edited 1 time in total.
Top
defenderBG
l33t
l33t
User avatar
Posts: 817
Joined: Tue Jun 20, 2006 4:43 pm

  • Quote

Post by defenderBG » Fri Jan 16, 2009 9:27 pm

can you post emerge -pv openssh?

it seems as if openssl was not compiled with kerberos installed.
Top
Kvetch
Guru
Guru
User avatar
Posts: 318
Joined: Thu Apr 29, 2004 1:42 am
Location: /dev/null, VA
Contact:
Contact Kvetch
Website

  • Quote

Post by Kvetch » Mon Jan 19, 2009 2:54 am

Thanks defenderBG. Not sure what the issue was but I emerged upgraded openssh, it pulled down no dependencies, ran revdep-rebuild and everything corrected itself.
Top
Post Reply

3 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic