[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#490883: openssh-server: logs some keys to /var/log/auth.log which is world readabl



Hi Witold,
* Witold Baryluk <baryluk@smp.if.uj.edu.pl> [2008-07-15 09:49]:
> (orginal key removed)
> 
> Jul 13 15:55:34 tytus sshd[24909]: error: key_read: uudecode AAAAB3NzaC1XXXXXXXX
> ........XXXXXXXRvB4h==\n failed
> Jul 13 15:55:36 tytus sshd[24909]: Accepted password for johnybravo from 10.0.1.1 port
>  49186 ssh2
> 
> 
> Ok, key have error, but it is probably one letter, or some whitespaces.
> Ok, it is public key, but sshd shouldn't log it anyway.

The public key is no sensitive data, I see no problem doing 
this. Besides that on a normal Debian installation this file 
is only readable for root and members of the adm group.

So something seems to be wrong with your system or the use 
you tried this with is in the adm group.

Kind regards
Nico
-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpFqItxtPoNM.pgp
Description: PGP signature


Reply to: