[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#609546: possibel bug in sshd: pubkey auth does not more work if ${HOME} is NFS



I have upgraded the second "Production System" to Squeeze on my Intranet
Server to check, wheter the bug affect squeeze and the test was positive

So again how to test it:

1)  You need two computers
    a)  a Server which use nfs-kernel-server to export /home/
    b)  a Workstation which mount /home/over NFS

2)  create a "user1" on the server
3)  create a "user2" on the server

4)  transfer the two passwords to the Workstaion and mount /home/
    over NFS

5)  now "user2" shuld login on the Workstation and is in his ${HOME}
    which is on the Server

6)  Yet, "user1" generate the id_dsa.key

7)  "user1" should now open a ssh session on the Workstation to the
    Server.
                NOW A PASSWORD (pam) IS REQUIRED

8)  copy "id_dsa.pub" to "user2" as "authorized_keys"

9)  now "user1" on the workstation does

       ssh -l user2 server:/home/user2

            NO PASSWORD IS REQUIRED

    which is correct

10) now "user1" want o log into his account without a password and copy
    "id_dsa.pub" to "authorized_keys" in his on ~/.ssh/ directory

                NOW A PASSWORD (pam) IS REQUIRED

    and pub_key_authentication does not more work.

How can we get back the old behaviour?

The behaviour from Lenny and Squeeze breaks any automated scripts.

Thanks, Greetings and nice Day/Evening
    Michelle Konzack

-- 
##################### Debian GNU/Linux Consultant ######################
   Development of Intranet and Embedded Systems with Debian GNU/Linux

itsystems@tdnet France EURL       itsystems@tdnet UG (limited liability)
Owner Michelle Konzack            Owner Michelle Konzack

Apt. 917 (homeoffice)
50, rue de Soultz                 Kinzigstraße 17
67100 Strasbourg/France           77694 Kehl/Germany
Tel: +33-6-61925193 mobil         Tel: +49-177-9351947 mobil
Tel: +33-9-52705884 fix

<http://www.itsystems.tamay-dogan.net/>  <http://www.flexray4linux.org/>
<http://www.debian.tamay-dogan.net/>         <http://www.can4linux.org/>

Jabber linux4michelle@jabber.ccc.de

Linux-User #280138 with the Linux Counter, http://counter.li.org/

Attachment: signature.pgp
Description: Digital signature


Reply to: