Re: ssh security update and libpam-tmpdir
On Tue, Jun 25, 2002 at 12:18:32AM +0100, Colin Watson wrote:
> If you have libpam-tmpdir installed, be careful when installing the
> recent security update for OpenSSH; libpam-tmpdir will stop working
> afterwards and cause ssh logins to be dropped (I've just filed a bug
> report).
>
> Since you almost certainly want to install the security update if you're
> running an ssh server visible to the net, the workaround is to edit
> /etc/pam.d/ssh and comment out the line for pam_tmpdir.
Also, in the hope of reducing the number of questions to
security@debian.org about this, don't worry that 'UsePrivilegeSeparation
yes' doesn't appear in /etc/ssh/sshd_config after the upgrade.
UsePrivilegeSeparation is on by default in OpenSSH 3.3.
--
Colin Watson [cjwatson@flatline.org.uk]
--
To UNSUBSCRIBE, email to debian-user-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply to: