Re: SSH and The requires_pre_auth attribute

2020-11-23 Thread Russ Allbery
"Dan Mahoney (Gushi)" writes: > 1) Is my "if it's on the host entry, it must be on the user entry" > basically accurate? Yes. Therefore, because of this, unless you are *certain* that every principal that needs to authenticate to another principal will have requires pre-auth set, you should no

SSH and The requires_pre_auth attribute

2020-11-23 Thread Dan Mahoney (Gushi)
Hey all. At the day job, we found that a user was able to log in to one system, but not another -- and the difference was that everyone who *could* log in had the requires_preauth attribute set on their principal, and newu...@dom.ain didn't. This was with password, not GSSAPI authentication (