Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: OpenSSH: Dev

Re: PermitUserEnvironment

 

 

OpenSSH dev RSS feed   Index | Next | Previous | View Threaded


drallen at cs

Jul 16, 2010, 2:26 PM

Post #1 of 2 (228 views)
Permalink
Re: PermitUserEnvironment

Daniel Allen wrote on May 26 18:14:31 EST 2010:
> Daniel Allen wrote on Fri Sep 4 23:46:12 EST 2009:
> > Damien Miller wrote:
> >
> > > We could make PermitUserEnvironment accept a pattern-list to
match
> > > environment variables, while retaining "yes", "no", "true" and
"false"
> > > as their current meanings of allow/deny-all.
> >
> > [...] The pattern-list would seem the more elegant approach for
our
> > use.
>
> I'd like to let you know that we're reviewing a patch which does
just as
> described, to accept a pattern for PermitUserEnvironment. It
affects vars
> defined in $HOME/.ssh/environment and authorized_keys. It
> accepts a single pattern, which is used as a case-insensitive
prefix for
> allowed variables. I will send along the patch as soon as I've had
a few
> colleagues review it.

And here, at last, is the patch, which will go into production in the
University
of Waterloo campus environment Real Soon Now. Feedback welcome.

Note that while the patch refers to openssh-5.4p1, it patches cleanly
against 5.5p1 as well. (I'd love to see this make it into the next
release!)

Thanks,
Daniel Allen
Computing Technology Specialist
Computer Science Computing Facility (CSCF)
David R. Cheriton School of Computer Science
University of Waterloo
(519) 888-4567 ext. 35448
drallen at uwaterloo dot ca


drallen at cs

Jul 19, 2010, 8:10 AM

Post #2 of 2 (244 views)
Permalink
Re: PermitUserEnvironment [In reply to]

On 16-Jul-10, at 5:26 PM, Daniel Allen wrote:

> And here, at last, is the patch, which will go into production in
> the University
> of Waterloo campus environment Real Soon Now. Feedback welcome.

For those reading along, the patch can be found at:
https://bugzilla.mindrot.org/show_bug.cgi?id=1800

Daniel Allen
Computing Technology Specialist
Computer Science Computing Facility (CSCF)
David R. Cheriton School of Computer Science
University of Waterloo
(519) 888-4567 ext. 35448
drallen at uwaterloo dot ca

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev [at] mindrot
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

OpenSSH dev RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.