[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#317777: Avoid thread support in ssh



Package: ssh
Version: 1:3.8.1p1-8.sarge.4

Hello,

At the moment, the PAM-Authentication-Module pam_krb5.so only works in
combination with ssh if ssh was compiled with thread-support (what is
not recommended by the upstream maintainers of ssh) and if in
/etc/ssh/sshd_config "UsePrivilegeSeparation" was set to "no" (what
reduces security). 

But on the project page of openssh there are already patches that make
the problematic thread-support superfluous and allow the use of
privilege separation. These patches can be found on:

http://bugzilla.mindrot.org/show_bug.cgi?id=688

I suggest to add these patches to Debian-ssh.

Christoph
 




Reply to: