Bugtraq mailing list archives

pam session


From: Christian Kraemer <ckraemer () ginko de>
Date: Tue, 19 Jun 2001 03:11:02 +0200

Hi,

Does anybody know why openssh (openssh-2.9p1) on a linux system does not call
pam_open_session if no pty is used? In this way the session modules (in
/etc/pam.d) are not activated.

This is espacially anoying if you
use pam_limits.so to set rlimits. Every user could
cirrcumvent them easily by calling ssh in this way:
ssh user@server /bin/sh

I do not know if this issue has been disscused before and if this behavior is
not alright .....

cu Christian 



Current thread: