Re: HEAD's UP: possible 0day SSH exploit in the wild

2009-07-08 Thread Sebastian Posner
Michael Stone wrote: [A way to enforce non-empty passwd on ssh-keys] > You can't, which is why it is useful to have both passwords and keys > simultaneously--you can enforce a policy on a password. To cite Noah Meyerhans from his recent mail - my users would shoot me if I ever tried such a thi

Re: HEAD's UP: possible 0day SSH exploit in the wild

2009-07-08 Thread Sebastian Posner
Jim Popovitch wrote: > > ALLOW rules and SSH-keys. > > Is there a way to force keys AND passwd verification? Normally you'd want to DISABLE PasswordAuthentication and ChallengeResponseAuthentication - unless you have a special and well-maintained setup like e.g. One-Time-Pads or such - because