SCIENTIFIC-LINUX-USERS Archives

July 2011

SCIENTIFIC-LINUX-USERS@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Sender:
Mailling list for Scientific Linux users worldwide <[log in to unmask]>
Date:
Fri, 15 Jul 2011 23:03:14 -0400
Reply-To:
Nico Kadel-Garcia <[log in to unmask]>
Content-Transfer-Encoding:
quoted-printable
Subject:
From:
Nico Kadel-Garcia <[log in to unmask]>
Content-Type:
text/plain; charset=ISO-8859-1
In-Reply-To:
MIME-Version:
1.0
Comments:
Parts/Attachments:
text/plain (30 lines)
On Fri, Jul 15, 2011 at 4:16 PM, Troy Dawson <[log in to unmask]> wrote:
> On 07/15/2011 02:25 PM, Steve Gaarder wrote:
>>
>> I notice that there are alternative SSH packages in the contrib
>> repository for SL 5.  In what way do these differ from the standard
>> packages?
>>
>> thanks,
>>
>
> Those were contributed by Fermilab.
> The client is patched so that it does both gssapi and gssapi-with-mic ...
> and a couple other authentication methods as well that I can't remember.
>
> Troy

The missing GSSAPI in the old OpenSSH 4.x releases in RHEL 5 are an
ongoing security issue. The GSSAPI modules allow genuine
"single-sign-on" behavior with an appropriate Kerberos or upstream
Active Directory setup (which is partly based on Kerberos).

Coupled with the Putty 0.61 release that came out a few days ago, It
makes single sign on in mixed environments a lot safer and easier to
manage, and helps avoid the security problems of ill-managed SSH keys
and people's refusal to properly protect, or even password protect,
the private keys they wander around with.

It's well worth the effort to switch to such better manageable,
revokable, and updatable authentication.

ATOM RSS1 RSS2