LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-08-2005, 09:16 PM   #1
swmok
Member
 
Registered: Jul 2003
Posts: 152

Rep: Reputation: 30
Urgent: sshd setup


Hello:

I want to setup the sshd such that it allows the root login(or a specific user) ONLY.

How to do that?

Many thanks.

swmok
 
Old 04-08-2005, 09:27 PM   #2
Joey.Dale
Member
 
Registered: Jun 2003
Location: Tampa, Fl
Distribution: Gentoo, Slackware
Posts: 828

Rep: Reputation: 39
One: Just because something is Urgent to you, doesn't mean its Urgent to everyone else.
Two: Please be more spicific
Three: read
Code:
man ssh_config
Four: Google is your friend.
Five: Please search before posting as I'm sure this has been asked before.

-Joey
 
Old 04-08-2005, 09:44 PM   #3
swmok
Member
 
Registered: Jul 2003
Posts: 152

Original Poster
Rep: Reputation: 30
First:
"Urgent" must be urgent to me. How can I know whether it is urgent to you?
I just want to express my feeling about my situation. Shouldn't I do this?

Second:
"Be specific". What's your point? How am I "non-specifie"? Pls. be specific to me.

Third:
I am asking about the setup of sshd. NOT ssh client.
I've read the file sshd_config.
There is a field to allows the login from a specific host NOT a specific user.

Fourth:
Thanks for your advice. However, could you pls. be more specific?
What keywords should I input?

Fifth:
How can you know "I haven't search the web."?
I just don't know how to search what I want.

Sixth:
If you're willing to help, just skip the post.
No need to blame others.
If you think the post is nonsense, talk to the admin. and kill this post.
 
Old 04-08-2005, 09:59 PM   #4
Joey.Dale
Member
 
Registered: Jun 2003
Location: Tampa, Fl
Distribution: Gentoo, Slackware
Posts: 828

Rep: Reputation: 39
Code:
echo "AllowUsers root" >> /etc/ssh/sshd_config
Where did I find that? In the sshd_config man page:
Quote:
AllowUsers
This keyword can be followed by a list of user name patterns, separated by spaces. If specified, login is allowed only for user names that match one of the patterns. `*' and `?' can be used as wildcards in the patterns. Only user names are valid; a numerical user ID is not recognized. By default, login is allowed for all users. If the pattern takes the form USER@HOST then USER and HOST are separately checked, restricting logins to particular users from particular hosts.
-Joey

Last edited by Joey.Dale; 04-08-2005 at 10:02 PM.
 
Old 04-08-2005, 10:18 PM   #5
swmok
Member
 
Registered: Jul 2003
Posts: 152

Original Poster
Rep: Reputation: 30
To Joey.Dale:

I apologize for my rudeness. Your help is so precious to me.

My urgent situation is that:
I am an admin of a over-100-user computer. 70% of them know nothing about computer and
their password is same as their username(So stupid, right?).
In the past few days, there are some hackers login to the computer and ruined the system.
I've just reinstall it and find the hackers AGAIN.

Your help let me know how to block these hackers and still allowing to do the admin job.

Thanks a lot and please accept my sincere apology.

swmok
 
Old 04-08-2005, 10:29 PM   #6
zeos
Member
 
Registered: Aug 2003
Posts: 150

Rep: Reputation: 15
Personally, I'd start by kicking my users squarely in their foreheads one at a time....

Then Setup public/private key auth for a non root user and only allow that user to logon via ssh with the AllowUsers directive. Then, add that user to the wheel group and set "su" to be executable only to users in "wheel" and root

Then you could log in with that user, using a rsa key/passphrase combo and su to root as needed
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSHD: No further authentication methods. URGENT ciaoci Linux - Security 4 10-08-2005 11:31 AM
Setup in sshd swmok Linux - Networking 1 12-31-2004 12:12 AM
Concepts/Security types/ Setup: OpenSSH/sshd/ssh/scp/sftp Caud Pong Linux - Security 5 09-23-2004 06:51 AM
how to setup/configure sshd pfaendtner Linux - Newbie 1 07-09-2004 04:18 PM
FTP Server Setup-URGENT REQUEST FOR HELP! scottpioso Linux - Networking 19 12-28-2003 09:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration