Re: configure ssh-access

2003-07-30 Thread Costas Magos
[EMAIL PROTECTED] wrote: Hi! I want to make ssh-access possible only from a restricted number of hosts - those that are named in /etc/hosts.allow. Users who want to login have a DynDNS host-name that shall be listed in hosts.allow to make it possible for users with a dial-up internet connecti

Re: configure ssh-access

2003-07-30 Thread Costas Magos
[EMAIL PROTECTED] wrote: Hi! I want to make ssh-access possible only from a restricted number of hosts - those that are named in /etc/hosts.allow. Users who want to login have a DynDNS host-name that shall be listed in hosts.allow to make it possible for users with a dial-up internet connection

Re: configure ssh-access

2003-07-10 Thread Peter Cordes
(I'm replying to the list, hope you don't mind.) On Thu, Jul 10, 2003 at 01:52:13PM +0200, Christian Kurz wrote: > On [09/07/03 16:12], Peter Cordes wrote: > > On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: > > > Le 12240i?me jour apr?s Epoch, > > > Mario Ohnewald ?crivait: > > >

Re: configure ssh-access

2003-07-10 Thread Peter Cordes
(I'm replying to the list, hope you don't mind.) On Thu, Jul 10, 2003 at 01:52:13PM +0200, Christian Kurz wrote: > On [09/07/03 16:12], Peter Cordes wrote: > > On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: > > > Le 12240i?me jour apr?s Epoch, > > > Mario Ohnewald ?crivait: > > >

Re: configure ssh-access

2003-07-09 Thread Ulrich Scholler
Hi, On Wed Jul 09, 2003 at 23:16:51 +0200, François TOURDE wrote: > > By allowing connections from only a > > few IP address blocks, you cut out most of the crackers in the world, but > > don't have to mess with dynamic DNS and lack of reverse lookup; A good > > tradeoff between security and con

Re: configure ssh-access

2003-07-09 Thread François TOURDE
Le 12242ième jour après Epoch, Peter Cordes écrivait: > On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: >> Le 12240i?me jour apr?s Epoch, >> Mario Ohnewald ?crivait: >> > I think this problem should not be solved with configuring sshd. >> >> Wrong... You can configure sshd to acc

Re: configure ssh-access

2003-07-09 Thread Ulrich Scholler
Hi, On Wed Jul 09, 2003 at 23:16:51 +0200, François TOURDE wrote: > > By allowing connections from only a > > few IP address blocks, you cut out most of the crackers in the world, but > > don't have to mess with dynamic DNS and lack of reverse lookup; A good > > tradeoff between security and con

Re: configure ssh-access

2003-07-09 Thread François TOURDE
Le 12242ième jour après Epoch, Peter Cordes écrivait: > On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: >> Le 12240i?me jour apr?s Epoch, >> Mario Ohnewald ?crivait: >> > I think this problem should not be solved with configuring sshd. >> >> Wrong... You can configure sshd to acc

Re: configure ssh-access

2003-07-09 Thread Peter Cordes
On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: > Le 12240i?me jour apr?s Epoch, > Mario Ohnewald ?crivait: > > I think this problem should not be solved with configuring sshd. > > Wrong... You can configure sshd to accept only login from recognized keys, > and let the firewall op

Re: configure ssh-access

2003-07-09 Thread Peter Cordes
On Mon, Jul 07, 2003 at 11:08:38AM +0200, [EMAIL PROTECTED] wrote: > Hi! > > I want to make ssh-access possible only from a restricted > number of hosts - those that are named in /etc/hosts.allow. > Users who want to login have a DynDNS host-name that shall > be listed in hosts.allow to make it po

Re: configure ssh-access

2003-07-09 Thread Peter Cordes
On Mon, Jul 07, 2003 at 07:38:17PM +0200, Fran?ois TOURDE wrote: > Le 12240i?me jour apr?s Epoch, > Mario Ohnewald ?crivait: > > I think this problem should not be solved with configuring sshd. > > Wrong... You can configure sshd to accept only login from recognized keys, > and let the firewall op

Re: configure ssh-access

2003-07-09 Thread Peter Cordes
On Mon, Jul 07, 2003 at 11:08:38AM +0200, [EMAIL PROTECTED] wrote: > Hi! > > I want to make ssh-access possible only from a restricted > number of hosts - those that are named in /etc/hosts.allow. > Users who want to login have a DynDNS host-name that shall > be listed in hosts.allow to make it po

Re: configure ssh-access

2003-07-07 Thread Kenneth Macdonald Karlsen
[EMAIL PROTECTED] wrote: Hi! I want to make ssh-access possible only from a restricted number of hosts - those that are named in /etc/hosts.allow. Users who want to login have a DynDNS host-name that shall be listed in hosts.allow to make it possible for users with a dial-up internet connection

Re: configure ssh-access

2003-07-07 Thread Kenneth Macdonald Karlsen
[EMAIL PROTECTED] wrote: Hi! I want to make ssh-access possible only from a restricted number of hosts - those that are named in /etc/hosts.allow. Users who want to login have a DynDNS host-name that shall be listed in hosts.allow to make it possible for users with a dial-up internet connection,

Re: configure ssh-access

2003-07-07 Thread François TOURDE
Le 12240ième jour après Epoch, Mario Ohnewald écrivait: > Hello! > >>-Original Message- >>From: Anne Carasik [mailto:[EMAIL PROTECTED] >>Sent: Monday, July 07, 2003 5:05 PM >>To: [EMAIL PROTECTED] >>Cc: debian-security@lists.debian.org >>Subject

Re: configure ssh-access

2003-07-07 Thread François TOURDE
Le 12240ième jour après Epoch, Mario Ohnewald écrivait: > Hello! > >>-Original Message- >>From: Anne Carasik [mailto:[EMAIL PROTECTED] >>Sent: Monday, July 07, 2003 5:05 PM >>To: [EMAIL PROTECTED] >>Cc: [EMAIL PROTECTED] >>Subject: Re: configure

RE: configure ssh-access

2003-07-07 Thread Mario Ohnewald
Hello! >-Original Message- >From: Anne Carasik [mailto:[EMAIL PROTECTED] >Sent: Monday, July 07, 2003 5:05 PM >To: [EMAIL PROTECTED] >Cc: debian-security@lists.debian.org >Subject: Re: configure ssh-access > > >Why not just limit the access through SSH publi

Re: configure ssh-access

2003-07-07 Thread Anne Carasik
Why not just limit the access through SSH public key? It sounds like that would accomplish what you're trying to do. -Anne [EMAIL PROTECTED] grabbed a keyboard and typed... > Hi! > > I want to make ssh-access possible only from a restricted > number of hosts - those that are named in /etc/hosts.

RE: configure ssh-access

2003-07-07 Thread Mario Ohnewald
Hello! >-Original Message- >From: Anne Carasik [mailto:[EMAIL PROTECTED] >Sent: Monday, July 07, 2003 5:05 PM >To: [EMAIL PROTECTED] >Cc: [EMAIL PROTECTED] >Subject: Re: configure ssh-access > > >Why not just limit the access through SSH public key? >It sou

Re: configure ssh-access

2003-07-07 Thread Anne Carasik
Why not just limit the access through SSH public key? It sounds like that would accomplish what you're trying to do. -Anne [EMAIL PROTECTED] grabbed a keyboard and typed... > Hi! > > I want to make ssh-access possible only from a restricted > number of hosts - those that are named in /etc/hosts.

Re: configure ssh-access

2003-07-07 Thread Adam ENDRODI
On Mon, Jul 07, 2003 at 11:08:38AM +0200, [EMAIL PROTECTED] wrote: > > I'd prefer to specify the rules for loggin into the machine > in the sshd_config-file, not in hosts.allow/deny. > But the AllowHosts/DenyHosts-options that could be used in > /etc/sshd_config earlier seem to be not any > longe

Re: configure ssh-access

2003-07-07 Thread Alan James
On Mon, 7 Jul 2003 11:08:38 +0200, [EMAIL PROTECTED] wrote: >The problem is that I can only login to the ssh-machine >when I enter the IP-address to the hosts.allow file. >Specifying the hosts DNS-name does not work! Thats probably because it does a reverse lookup on the connecting ip to see if i

Re: configure ssh-access

2003-07-07 Thread Adam ENDRODI
On Mon, Jul 07, 2003 at 11:08:38AM +0200, [EMAIL PROTECTED] wrote: > > I'd prefer to specify the rules for loggin into the machine > in the sshd_config-file, not in hosts.allow/deny. > But the AllowHosts/DenyHosts-options that could be used in > /etc/sshd_config earlier seem to be not any > longe

Re: configure ssh-access

2003-07-07 Thread Alan James
On Mon, 7 Jul 2003 11:08:38 +0200, [EMAIL PROTECTED] wrote: >The problem is that I can only login to the ssh-machine >when I enter the IP-address to the hosts.allow file. >Specifying the hosts DNS-name does not work! Thats probably because it does a reverse lookup on the connecting ip to see if i