[ 
https://issues.apache.org/jira/browse/SSHD-584?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Alon Bar-Lev reopened SSHD-584:
-------------------------------

Hi,
Please see OpenSSH maintainer response[1].
The wiki is not a formal source of information.
The behaviour implemented in the OpenSSH is the intended one.
The configuration file should be either owned by root or by user, not writeable 
by world nor group.
Thanks,
Alon

[1] 
http://lists.mindrot.org/pipermail/openssh-unix-dev/2015-November/034520.html

> permisison of ~/.ssh/config with group/world readable is legal
> --------------------------------------------------------------
>
>                 Key: SSHD-584
>                 URL: https://issues.apache.org/jira/browse/SSHD-584
>             Project: MINA SSHD
>          Issue Type: Bug
>    Affects Versions: 1.1.0
>         Environment: build
>            Reporter: Alon Bar-Lev
>
> Got this exception:
> ---
> testAttributes(org.apache.sshd.client.subsystem.sftp.SftpFileSystemTest)  
> Time elapsed: 5.581 sec  <<< ERROR!
> java.io.IOException: String permission violation (GROUP_READ) for 
> /home/alonbl/.ssh/config
>         at 
> org.apache.sshd.client.config.hosts.DefaultConfigFileHostEntryResolver.reloadHostConfigEntries(DefaultConfigFileHostEntryResolver.java:80)
>         at 
> org.apache.sshd.client.config.hosts.ConfigFileHostEntryResolver.resolveEffectiveResolver(ConfigFileHostEntryResolver.java:86)
>         at 
> org.apache.sshd.client.config.hosts.ConfigFileHostEntryResolver.resolveEffectiveHost(ConfigFileHostEntryResolver.java:59)
>         at org.apache.sshd.client.SshClient.connect(SshClient.java:339)
>         at 
> org.apache.sshd.client.subsystem.sftp.SftpFileSystemProvider.newFileSystem(SftpFileSystemProvider.java:177)
>         at 
> org.apache.sshd.client.subsystem.sftp.SftpFileSystemProvider.newFileSystem(SftpFileSystemProvider.java:87)
>         at java.nio.file.FileSystems.newFileSystem(FileSystems.java:322)
>         at java.nio.file.FileSystems.newFileSystem(FileSystems.java:272)
>         at 
> org.apache.sshd.client.subsystem.sftp.SftpFileSystemTest.testAttributes(SftpFileSystemTest.java:136)
> ---
> While ssh code enforces only world/group writeable at 
> readconf.c::read_config_file:
> ---
>         if (flags & SSHCONF_CHECKPERM) {
>                 struct stat sb;
>                 if (fstat(fileno(f), &sb) == -1)
>                         fatal("fstat %s: %s", filename, strerror(errno));
>                 if (((sb.st_uid != 0 && sb.st_uid != getuid()) ||
>                     (sb.st_mode & 022) != 0))
>                         fatal("Bad owner or permissions on %s", filename);
>         }
> ---



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to