Re: sshd.config and AllowUsers

Previous thread: Re: Problem on installing new packages by Stephen Liu on Monday, March 26, 2007 - 10:26 am. (1 message)

Next thread: i386 Crash after a certain uptime ? by Landry Breuil on Monday, March 26, 2007 - 11:22 am. (1 message)
From: Jerome Santos
Date: Monday, March 26, 2007 - 10:33 am

I have a few seperate users on my server, one user for which I want to
dissallow ssh login. Now I've read the man page for sshd and I've read a lot
of the documentation on this, but I'm still not clear one one point. By
default, /etc/ssh/sshd.config shows all entries are commented out. I want to
add something like this:

AllowUsers user1, user2, user3

I added that in but also with an # in front like all the other entries. Now
I find that I can still ssh to the box with a user acct that I didn't
include in the entry. Should it be in there without the #? And if so, do I
also then have to uncomment all the other entries??

Thanks

From: Tim Kuhlman
Date: Monday, March 26, 2007 - 11:07 am

man sshd_config
In the first paragraph you will find the line "Lines starting with `#' and 
empty lines are interpreted as comments." The default config file is full of 
examples that are commented out which are the lines you see.

-- 
Tim Kuhlman
Network Administrator
ColoradoVnet.com

From: openbsd misc
Date: Monday, March 26, 2007 - 11:09 am

Hello,

everything is commented because these are the default settings. If you want to
change a setting you'll have to uncomment and change it.


Regards
  Hagen Volpers

-----Urspr|ngliche Nachricht-----
Von: owner-misc@openbsd.org [mailto:owner-misc@openbsd.org] Im Auftrag von
Jerome Santos
Gesendet: Montag, 26. Mdrz 2007 19:33
An: misc@openbsd.org
Betreff: sshd.config and AllowUsers

I have a few seperate users on my server, one user for which I want to
dissallow ssh login. Now I've read the man page for sshd and I've read a lot
of the documentation on this, but I'm still not clear one one point. By
default, /etc/ssh/sshd.config shows all entries are commented out. I want to
add something like this:

AllowUsers user1, user2, user3

I added that in but also with an # in front like all the other entries. Now
I find that I can still ssh to the box with a user acct that I didn't
include in the entry. Should it be in there without the #? And if so, do I
also then have to uncomment all the other entries??

Thanks

From: Will Maier
Date: Monday, March 26, 2007 - 11:14 am

No, they're the default settings.

-- 

o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net |
*------------------[ BSD Unix: Live Free or Die ]------------------*

From: Serge Basterot
Date: Monday, March 26, 2007 - 12:09 pm

Hello,

On Mon, Mar 26, 2007 at 01:33:17PM -0400, Jerome Santos wrote:


AllowUsers is a list of "user name patterns, separated by _spaces_".
Also take a look at the AllowGroups parameter.

-- 
Serge

From: Jerome Santos
Date: Monday, March 26, 2007 - 1:38 pm

Thanks for pointing me in the right direction, got it working properly now;
found out the hard way to separate users by whitespace only, NOT commas.

thanks


From: Lars D. Noodén
Date: Monday, March 26, 2007 - 9:59 pm

Others have mentioned the correct syntax already.  One suggestion which
helps administration is to assign or revoke access (or other privileges)
based on groups rather than individual users.  In otherwords, make the
users members of a group and grant that group access.

It helps scalability, maintenance, and testing.

Regards,
-Lars

Lars NoodC)n (larsnooden@openoffice.org)
         Ensure access to your data now and in the future
         http://opendocumentfellowship.org/about_us/contribute

Previous thread: Re: Problem on installing new packages by Stephen Liu on Monday, March 26, 2007 - 10:26 am. (1 message)

Next thread: i386 Crash after a certain uptime ? by Landry Breuil on Monday, March 26, 2007 - 11:22 am. (1 message)