From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 11150 invoked by alias); 14 Mar 2019 09:47:54 -0000 Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner@cygwin.com Mail-Followup-To: cygwin@cygwin.com Received: (qmail 11143 invoked by uid 89); 14 Mar 2019 09:47:54 -0000 Authentication-Results: sourceware.org; auth=none X-Spam-SWARE-Status: No, score=-102.6 required=5.0 tests=AWL,BAYES_00,GOOD_FROM_CORINNA_CYGWIN,RCVD_IN_DNSWL_NONE autolearn=ham version=3.3.1 spammy=HTo:U*bruce, password, H*F:D*cygwin.com, risk X-HELO: mout.kundenserver.de Received: from mout.kundenserver.de (HELO mout.kundenserver.de) (212.227.126.134) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Thu, 14 Mar 2019 09:47:52 +0000 Received: from calimero.vinschen.de ([24.134.7.25]) by mrelayeu.kundenserver.de (mreue012 [212.227.15.167]) with ESMTPSA (Nemesis) id 1MVJZv-1hVczk1KH1-00SLbk; Thu, 14 Mar 2019 10:47:47 +0100 Received: by calimero.vinschen.de (Postfix, from userid 500) id EDD22A80746; Thu, 14 Mar 2019 10:47:45 +0100 (CET) Date: Thu, 14 Mar 2019 09:47:00 -0000 From: Corinna Vinschen To: Bruce Halco Cc: cygwin@cygwin.com Subject: Re: seteuid problem with sshd Message-ID: <20190314094745.GD3785@calimero.vinschen.de> Reply-To: cygwin@cygwin.com Mail-Followup-To: Bruce Halco , cygwin@cygwin.com References: <68371e6b-aee9-4e70-d079-098160f7bf61@halcomp.com> <1231848485.20190314025011@yandex.ru> <032d1268-15e7-f10d-bdd7-45effb6b6a2b@halcomp.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="UGQe+kC6sZm6KOhh" Content-Disposition: inline In-Reply-To: <032d1268-15e7-f10d-bdd7-45effb6b6a2b@halcomp.com> User-Agent: Mutt/1.11.3 (2019-02-01) X-SW-Source: 2019-03/txt/msg00362.txt.bz2 --UGQe+kC6sZm6KOhh Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-length: 1884 On Mar 13 22:20, Bruce Halco wrote: > I had found nothing referencing "No such file or directory", which sounds > rather different from a permissions problem. >=20 > Running sshd under the Local System account made no difference. >=20 > passwd -R was no help. >=20 > What I did discover was that cygwin/sshd apparently now requires the Wind= ows > account to be Enabled.=C2=A0 That was not the case previously. >=20 > The target systems in my application are in restaurant offices, and only = use > a single Windows login. >=20 > As the people who use ssh do not need local Windows accounts, I've always > used the practice of Disabling those user accounts in Windows. The > credentials were available to ssh, without the security issues of all tho= se > extra active accounts. >=20 > Unless someone can suggest an alternative, I'll have to leave all those > accounts Enabled. I can put some long, nasty passwords on them to keep the > risk acceptable. I'm sorry to say that, but there is no alternative. This has been discussed at great length on thlis mailing list, starting at https://cygwin.com/ml/cygwin/2019-01/msg00197.html For starters, I added a special check to disable logging in with a disabled account. However, the S4U logon method used by Cygwin now in place of the old "Create user token from scratch" method(*) even checks that automatically and does not allow disabled accounts to logon. Same goes for the `passwd -R' method as well as for normal password logon since they have been introduced, btw, given they use the same underlying WIndows function which actively checks for disabled accounts. Last but not least, the fact that some logon methods allowed disabled accounts to logon and some didn't wasn't really a good idea to begin with. Corinna (*) https://cygwin.com/cygwin-ug-net/ntsec.html#ntsec-nopasswd1 --=20 Corinna Vinschen Cygwin Maintainer --UGQe+kC6sZm6KOhh Content-Type: application/pgp-signature; name="signature.asc" Content-length: 833 -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEoVYPmneWZnwT6kwF9TYGna5ET6AFAlyKI0EACgkQ9TYGna5E T6ABfA/8Csnssc2kRWk0jtoIXJ5dS/QtmxajIskM0CYOyAlmFtsxlqnG3mqCMkCh a2uyQGaQ3Z1z01DusDH2awXS3IZcIQ3Gqw4Jswryw0OqoM9357jakaufFkL87OMf doFbq7HoSbifsZGIzsGuEN331Pwbr+yjLcRMDixWAK0p0lLYklYgTllyv0UGTES7 DaZweGsktAbQh7zZ7lJwaafVIRgf09MifgKzkk4bwnchMd/c4jW40JI4rm/KlShh DWBwm/9dEmREKQycllrwLDsZ1J1I03rLzNi4YzhSixO+f8tnRtNtMyeqS0NFVKel hd436JOaASGtSgRnp8jV0guSKUdjMLtkJWVeM+L/usV7mYLnkbzRqtiKU0moT413 JNSbDWocd/l2kGa200LGjFIZlPqnmSyPaZyiGVmGWjfq24m+XQPaa4x3lWbQO3Be YGMafvMi5Ot2g3BGy/m9bYc/wftSWCEncORzXjAWP14AtqLnffLCe5cctUehNVmU gz+cww/UMsYuPrgGBguIkJyfY0bGAZGPmHCFKHauAkOmFoPn9/XYjyQzFCHxxiXY bCKbagFLpC2A1DlW3c8+nlqKxgMr84fKcI9HAb5gw3SbZF9QFU3UFy2cSkWUG026 /1t/rPdQ/7KOW621mweb9SsZeC1YEx81ysuty0Sc4YQjTSn9mZ4= =u5D7 -----END PGP SIGNATURE----- --UGQe+kC6sZm6KOhh--