[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#198254: marked as done (ssh: /etc/pam.d/ssh requires pam_limits)



Your message dated Sun, 04 Jan 2004 14:32:12 -0500
with message-id <E1AdDyu-0002N5-00@auric.debian.org>
and subject line Bug#198254: fixed in openssh 1:3.6.1p2-11
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 21 Jun 2003 00:09:49 +0000
>From scott@tranzoa.net Fri Jun 20 19:09:48 2003
Return-path: <scott@tranzoa.net>
Received: from dsl254-027-160.sea1.dsl.speakeasy.net (mail.tranzoa.net) [216.254.27.160] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 19TVwx-0007TQ-00; Fri, 20 Jun 2003 19:09:48 -0500
Received: from mail.mvdomain (asuka.mvdomain [10.1.1.45])
	by mail.tranzoa.net (Postfix) with ESMTP id DDBB78345
	for <submit@bugs.debian.org>; Fri, 20 Jun 2003 17:09:43 -0700 (PDT)
Received: from tara.mvdomain (voltron.mvdomain [10.1.1.40])
	by mail.mvdomain (Postfix) with ESMTP id C93071312D
	for <submit@bugs.debian.org>; Fri, 20 Jun 2003 17:09:41 -0700 (PDT)
Received: by tara.mvdomain (Postfix, from userid 1000)
	id F3F3C20C066; Fri, 20 Jun 2003 17:09:41 -0700 (PDT)
From: Scott Robinson <scott@tranzoa.net>
Subject: ssh: /etc/pam.d/ssh requires pam_limits
To: submit@bugs.debian.org
X-Mailer: bug 3.3.10.2
Message-Id: <20030621000941.F3F3C20C066@tara.mvdomain>
Date: Fri, 20 Jun 2003 17:09:41 -0700 (PDT)
Delivered-To: submit@bugs.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0
	tests=BAYES_30,HAS_PACKAGE
	version=2.53-bugs.debian.org_2003_06_18
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 2.53-bugs.debian.org_2003_06_18 (1.174.2.15-2003-03-30-exp)

Package: ssh
Version: 1:3.6.1p2-2
Severity: normal

/etc/pam.d/ssh has a line requiring pam_limits. In a default configuration,
this will cause security alerts to appear in the system logs.

I would recommend commenting out the line and adding the comments similar to
those in /etc/pam.d/login:

# Sets up user limits, please uncomment and read /etc/security/limits.conf
# to enable this functionality.
# (Replaces the use of /etc/limits in old login)
# session    required   pam_limits.so

-- System Information
Debian Release: testing/unstable
Kernel Version: Linux tara 2.4.21 #1 Sat Jun 14 04:48:49 PDT 2003 i686 GNU/Linux

Versions of the packages ssh depends on:
ii  adduser        3.50           Add and remove users and groups
ii  debconf        1.2.35         Debian configuration management system
ii  libc6          2.3.1-16       GNU C Library: Shared libraries and Timezone
ii  libpam-modules 0.76-9         Pluggable Authentication Modules for PAM
ii  libpam0g       0.76-9         Pluggable Authentication Modules library
ii  libssl0.9.7    0.9.7b-2       SSL shared libraries
ii  libwrap0       7.6-ipv6.1-3   Wietse Venema's TCP wrappers library
ii  zlib1g         1.1.4-12       compression library - runtime

---------------------------------------
Received: (at 198254-close) by bugs.debian.org; 4 Jan 2004 22:32:01 +0000
>From katie@auric.debian.org Sun Jan 04 16:32:01 2004
Return-path: <katie@auric.debian.org>
Received: from auric.debian.org [206.246.226.45] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1AdE1k-0000tE-00; Sun, 04 Jan 2004 13:35:08 -0600
Received: from katie by auric.debian.org with local (Exim 3.35 1 (Debian))
	id 1AdDyu-0002N5-00; Sun, 04 Jan 2004 14:32:12 -0500
From: Colin Watson <cjwatson@debian.org>
To: 198254-close@bugs.debian.org
X-Katie: $Revision: 1.43 $
Subject: Bug#198254: fixed in openssh 1:3.6.1p2-11
Message-Id: <E1AdDyu-0002N5-00@auric.debian.org>
Sender: Archive Administrator <katie@auric.debian.org>
Date: Sun, 04 Jan 2004 14:32:12 -0500
Delivered-To: 198254-close@bugs.debian.org

Source: openssh
Source-Version: 1:3.6.1p2-11

We believe that the bug you reported is fixed in the latest version of
openssh, which is due to be installed in the Debian FTP archive:

openssh_3.6.1p2-11.diff.gz
  to pool/main/o/openssh/openssh_3.6.1p2-11.diff.gz
openssh_3.6.1p2-11.dsc
  to pool/main/o/openssh/openssh_3.6.1p2-11.dsc
ssh-askpass-gnome_3.6.1p2-11_powerpc.deb
  to pool/main/o/openssh/ssh-askpass-gnome_3.6.1p2-11_powerpc.deb
ssh_3.6.1p2-11_powerpc.deb
  to pool/main/o/openssh/ssh_3.6.1p2-11_powerpc.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 198254@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <cjwatson@debian.org> (supplier of updated openssh package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun,  4 Jan 2004 18:59:21 +0000
Source: openssh
Binary: ssh-askpass-gnome ssh
Architecture: source powerpc
Version: 1:3.6.1p2-11
Distribution: unstable
Urgency: low
Maintainer: Matthew Vernon <matthew@debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description: 
 ssh        - Secure rlogin/rsh/rcp replacement (OpenSSH)
 ssh-askpass-gnome - under X, asks user for a passphrase for ssh-add
Closes: 198254 215252 225238
Changes: 
 openssh (1:3.6.1p2-11) unstable; urgency=low
 .
   * Comment out pam_limits in default configuration, for now at least
     (closes: #198254).
   * Use invoke-rc.d (if it exists) to run the init script.
   * Backport format string bug fix in sshconnect.c (closes: #225238).
   * ssh-copy-id exits if ssh fails (closes: #215252).
Files: 
 7cf8d103a100fb8f432b3130238aaf8c 850 net standard openssh_3.6.1p2-11.dsc
 33bfe634709affc976dfe30fa44b7fd2 102586 net standard openssh_3.6.1p2-11.diff.gz
 84b5d76b76ff27863d92f0d75dc07432 704188 net standard ssh_3.6.1p2-11_powerpc.deb
 9b5fccd74799f58643aba7d4baf449ba 44940 gnome optional ssh-askpass-gnome_3.6.1p2-11_powerpc.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Colin Watson <cjwatson@debian.org> -- Debian developer

iD8DBQE/+Gal9t0zAhD6TNERAm1lAJ9xe6ilU7r+b6hEoVQcQvpCNrRxrACdEctG
9T8uH1l2mcrRk6v5Wbkmlac=
=rfB+
-----END PGP SIGNATURE-----




Reply to: