[Bug 66095] [pam] template_user is broken in pam_radius

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Thu Dec 17 20:04:41 UTC 2015


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=66095

Dag-Erling Smørgrav <des at FreeBSD.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |des at FreeBSD.org
         Resolution|FIXED                       |Rejected

--- Comment #6 from Dag-Erling Smørgrav <des at FreeBSD.org> ---
The problem is that OpenSSH checks whether the user exists before attempting
authentication.  Moreover, the OpenSSH developers consider this functionality a
security liability and have intentionally removed it from their code (see
https://blog.des.no/2015/08/openssh-pam-and-user-names/).  Therefore, we will
not fix this.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-bugs mailing list