[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ssh security update and libpam-tmpdir



On Tue, Jun 25, 2002 at 12:18:32AM +0100, Colin Watson wrote:
> If you have libpam-tmpdir installed, be careful when installing the
> recent security update for OpenSSH; libpam-tmpdir will stop working
> afterwards and cause ssh logins to be dropped (I've just filed a bug
> report).
> 
> Since you almost certainly want to install the security update if you're
> running an ssh server visible to the net, the workaround is to edit
> /etc/pam.d/ssh and comment out the line for pam_tmpdir.

Also, in the hope of reducing the number of questions to
security@debian.org about this, don't worry that 'UsePrivilegeSeparation
yes' doesn't appear in /etc/ssh/sshd_config after the upgrade.
UsePrivilegeSeparation is on by default in OpenSSH 3.3.

-- 
Colin Watson                                  [cjwatson@flatline.org.uk]


-- 
To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org



Reply to: