From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 83726 invoked by alias); 24 Jan 2019 16:16:51 -0000 Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner@cygwin.com Mail-Followup-To: cygwin@cygwin.com Received: (qmail 83707 invoked by uid 89); 24 Jan 2019 16:16:50 -0000 Authentication-Results: sourceware.org; auth=none X-Spam-SWARE-Status: =?ISO-8859-1?Q?No, score=-0.9 required=5.0 tests=BAYES_00,KAM_LAZY_DOMAIN_SECURITY,RCVD_IN_DNSWL_NONE autolearn=no version=3.3.2 spammy=8:t, 8:un, 8:ha, 8:=c3=a4?= X-HELO: mout.kundenserver.de Received: from mout.kundenserver.de (HELO mout.kundenserver.de) (212.227.17.10) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Thu, 24 Jan 2019 16:16:47 +0000 Received: from [192.168.0.15] ([149.172.203.221]) by mrelayeu.kundenserver.de (mreue109 [212.227.15.145]) with ESMTPSA (Nemesis) id 1McH1O-1hKfS41UwG-00ceLs for ; Thu, 24 Jan 2019 17:16:44 +0100 Subject: Re: sshd permits logon using disabled user? To: cygwin@cygwin.com References: <20190124154533.GK2802@calimero.vinschen.de> <2b348ac3-63d1-2cd3-430d-2568d650a583@baur-itcs.de> <20190124155918.GL2802@calimero.vinschen.de> From: Stefan Baur Openpgp: preference=signencrypt Message-ID: <51ded8a7-ffc0-c1b0-8bb6-8d2f5870ec68@baur-itcs.de> Date: Thu, 24 Jan 2019 16:16:00 -0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.2.1 MIME-Version: 1.0 In-Reply-To: <20190124155918.GL2802@calimero.vinschen.de> Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="VZtROTBkf0XOqmAigdpMpnCmPnPE03HXr" X-IsSubscribed: yes X-SW-Source: 2019-01/txt/msg00202.txt.bz2 --VZtROTBkf0XOqmAigdpMpnCmPnPE03HXr Content-Type: multipart/mixed; boundary="P1tLbfwDBtd0AaqCLLWm0ELtVRlSOJgCe"; protected-headers="v1" From: Stefan Baur To: cygwin@cygwin.com Message-ID: <51ded8a7-ffc0-c1b0-8bb6-8d2f5870ec68@baur-itcs.de> Subject: Re: sshd permits logon using disabled user? References: <20190124154533.GK2802@calimero.vinschen.de> <2b348ac3-63d1-2cd3-430d-2568d650a583@baur-itcs.de> <20190124155918.GL2802@calimero.vinschen.de> In-Reply-To: <20190124155918.GL2802@calimero.vinschen.de> --P1tLbfwDBtd0AaqCLLWm0ELtVRlSOJgCe Content-Type: text/plain; charset=utf-8 Content-Language: de-DE Content-Transfer-Encoding: quoted-printable Content-length: 1097 Am 24.01.19 um 16:59 schrieb Corinna Vinschen: > I think refusing an account manually and deliberately disabled by an > admin makes lots of sense. >=20 > I'm not so sure about locked out accounts. THis might need some > discussion. It's been a while since I did Windows administration, so I can't really make a recommendation here ... BUT: If an admin can lock out an account (separately from disabling it entirely), say, by setting an initial password, checking the "user must change password on first login", and also checking "user is not allowed to change password" simultaneously (if that's possible), or, say, by just setting a random password without telling it to anyone ever, followed by firing so many login attempts at the account that it gets locked out, then telling them apart and treating locked out accounts differently would make sense, IMO. Kind Regards, Stefan Baur --=20 BAUR-ITCS UG (haftungsbeschr=C3=A4nkt) Gesch=C3=A4ftsf=C3=BChrer: Stefan Baur Eichen=C3=A4ckerweg 10, 89081 Ulm | Registergericht Ulm, HRB 724364 Fon/Fax 0731 40 34 66-36/-35 | USt-IdNr.: DE268653243 --P1tLbfwDBtd0AaqCLLWm0ELtVRlSOJgCe-- --VZtROTBkf0XOqmAigdpMpnCmPnPE03HXr Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" Content-length: 473 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJcSeTlAAoJEG7d9BjNvlEZ7SAH/1tmwc8kuUz5TmZxanLRdDIn Wwk2PnGjnbik5ZE0Wq32PUNEuN1xibsx0WBX1zTeOTtjctXg4seu2GtLyMlxWPWs e3cFxS4phIvCOvk6grXVaRQGBD2JUFK8AG5ZBpXh90pCsvyEtqhbQ4cZp/ZgXYLM 3uMcLKzo72SYhjGahuKZ2PKUxCbUq2EZ1bzPtKvsKv2s6WqwUj4n2yudtX9w83pT eJtkF4xD8TV0JXsuBu7L5JUB72tbhNLx4seJaecr7LaPtuksVrNMf57uZ3flqrkX LFrMgXUf15J6KoyScE0cw494CTZFX19Vjad2dULj2gudbW4CITPPrklla4t3w5c= =wpfU -----END PGP SIGNATURE----- --VZtROTBkf0XOqmAigdpMpnCmPnPE03HXr--