Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248094
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Unlocking (remote/local), was Re: Help with suid (bash) |
| Date | 2022-05-11 18:10 +0200 |
| Message-ID | <ElX4t-eNbJ-5@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <Elz29-eyP5-1@gated-at.bofh.it> <ElAAV-ezOV-3@gated-at.bofh.it> <ElHj3-eDJa-1@gated-at.bofh.it> <ElKTE-eFZj-1@gated-at.bofh.it> <ElMLL-eH9t-35@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed 11 May 2022 at 07:05:47 (+0200), tomas@tuxteam.de wrote: > On Tue, May 10, 2022 at 10:08:20PM -0500, David Wright wrote: > > On Tue 10 May 2022 at 17:12:25 (-0600), Charles Curley wrote: > > [...] > > > IOW, though logging in to root by password is ok at the console, > > it's not ok when remote. ➀ > > I assume you know all that you can set "PermitRootLogin yes" in > your /etc/ssh/sshd_config (the default is "prohibit-password", > which fits the behaviour you are describing). > > It's not recommended, (for good reasons!), but hey, it's your box, > and you decide what you deem to be "secure enough". After all, > security is context-dependent, and the worst antipattern is to > misuse tech to force people to follow some nonsensical rituals > (it happens far too often, alas, but OpenSSH isn't that sort of > software). > > So you can change that, if you wish so. What's your point? Well, Charles seemed to have difficulty with understanding my first paragraph, which I wrote merely to explain that I assume a root password has been set. It seems odd to get three follow-ups, all of which centre on the consequences of the ssh configuration chosen by the Debian developers for a bullseye installation. When you write a script to unlock and mount a partition, you can do it in two lines: # udisksctl unlock --block-device /dev/foo # mount /dev/bar /baz but that's useless as it stands, and needs to be embedded into your ecosystem to be useful, which is why I posted my script, a real example. But after two posts about background information on setuid shell scripts, you now write "the worst antipattern is to misuse tech to force people to follow some nonsensical rituals". Strong words. Perhaps you could elaborate on which specific rituals you find offensive. I can't work out whether you're criticising my script, or the Debian developers for the way they're now choosing to configure ssh, or the linux kernel developers for the ban on setuid shell scripts. Cheers, David.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200
csiph-web