public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* SSHD pubkey authentication
@ 2001-04-24  4:36 Lapo Luchini
  2001-04-24  5:53 ` Corinna Vinschen
  2001-04-24  6:17 ` Mail list page Vince Rice
  0 siblings, 2 replies; 7+ messages in thread
From: Lapo Luchini @ 2001-04-24  4:36 UTC (permalink / raw)
  To: cygwin

It is possible to use pubkey authentication on NT?
I played a lot with ntsec,nontsec,ntea,nontea starting serrvice as
SYSTEM or as administrator

Result is that the SYSTEM user can't access
/home/*/.ssh/authorized_keys[2] no matter the modes or owners, only way
to use pubkey auth is to start the service as the user that wants to
connect, not a real solution..

As anyone got better?

I mean using the OpenSSH distro available now.

Thanks =)

--
Lapo 'Raist' Luchini
lapo@lapo.it (PGP & X.509 keys available)
http://www.lapo.it (ICQ UIN: 529796)



--
Want to unsubscribe from this list?
Check out: http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 7+ messages in thread
* Re: SSHD pubkey authentication
@ 2001-04-24  5:58 Lapo Luchini
  0 siblings, 0 replies; 7+ messages in thread
From: Lapo Luchini @ 2001-04-24  5:58 UTC (permalink / raw)
  To: cygwin

> The reason is the restriction for changing user context on NT/W2K.
> You can do this only by providing the password of that user, even
> if the process is running under LocalSystem account.
I feared that =(

Thanks anyway for the confirm =)

> > I mean using the OpenSSH distro available now.
> I don't understand what you try to say with that sentence.
I meant something like: please don't answer me "just patch, hack,
recompile and you can do it"
The problem with recompiling is that I must use ssh in a system which is
not mine ans they would not accept to use a "ercompiled" version of ssh.
Anyway the problem is at the source of W2K authentication as you said,
so there is no such problem...

--
Lapo 'Raist' Luchini
lapo@lapo.it (PGP & X.509 keys available)
http://www.lapo.it (ICQ UIN: 529796)

--
Want to unsubscribe from this list?
Check out: http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 7+ messages in thread
* Re: SSHD pubkey authentication
@ 2001-05-01  7:34 Lapo Luchini
  2001-05-02  6:17 ` Corinna Vinschen
  0 siblings, 1 reply; 7+ messages in thread
From: Lapo Luchini @ 2001-05-01  7:34 UTC (permalink / raw)
  To: cygwin

> The reason is the restriction for changing user context on NT/W2K.
> You can do this only by providing the password of that user, even
> if the process is running under LocalSystem account.
>
But then how can IIS authenticate (in https) using only private key?

Of course they have some special access to some special not documented
API to change active user?

--
Lapo 'Raist' Luchini
lapo@lapo.it (PGP & X.509 keys available)
http://www.lapo.it (ICQ UIN: 529796)



--
Want to unsubscribe from this list?
Check out: http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2001-05-02  6:17 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2001-04-24  4:36 SSHD pubkey authentication Lapo Luchini
2001-04-24  5:53 ` Corinna Vinschen
2001-04-24  6:17 ` Mail list page Vince Rice
2001-04-24  8:29   ` Christopher Faylor
2001-04-24  5:58 SSHD pubkey authentication Lapo Luchini
2001-05-01  7:34 Lapo Luchini
2001-05-02  6:17 ` Corinna Vinschen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).