Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: OpenSSH: Dev

FW: ulimits in ssh/sshd without resorting to PAM?

 

 

OpenSSH dev RSS feed   Index | Next | Previous | View Threaded


michael.hebenstreit at intel

Aug 2, 2012, 9:07 AM

Post #1 of 4 (305 views)
Permalink
FW: ulimits in ssh/sshd without resorting to PAM?

Is there an (even rudimentary) way to compile/configure/use ulimits in ssh/sshd without resorting to PAM?

I've searched docs and archives, but did not find anything

Thanks
Michael

Sorry for posting on this list, but secureshell [at] securityfocus did not distribute my mail :(

------------------------------------------------------------------------
Michael Hebenstreit Senior Cluster Architect
Intel Corporation Software and Services Group/HTE
2800 N Center Dr, DP3-307 Tel.: +1 253 371 3144
WA 98327, DuPont
UNITED STATES E-mail: michael.hebenstreit [at] intel

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev [at] mindrot
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev


djm at mindrot

Aug 5, 2012, 3:56 PM

Post #2 of 4 (281 views)
Permalink
Re: FW: ulimits in ssh/sshd without resorting to PAM? [In reply to]

On Thu, 2 Aug 2012, Hebenstreit, Michael wrote:

> Is there an (even rudimentary) way to compile/configure/use ulimits in
> ssh/sshd without resorting to PAM?
>
> I've searched docs and archives, but did not find anything

You might have to use a custom login shell.

-d
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev [at] mindrot
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev


dtucker at zip

Aug 5, 2012, 6:08 PM

Post #3 of 4 (279 views)
Permalink
Re: FW: ulimits in ssh/sshd without resorting to PAM? [In reply to]

On Mon, Aug 6, 2012 at 8:56 AM, Damien Miller <djm [at] mindrot> wrote:
> On Thu, 2 Aug 2012, Hebenstreit, Michael wrote:
>
>> Is there an (even rudimentary) way to compile/configure/use ulimits in
>> ssh/sshd without resorting to PAM?
>>
>> I've searched docs and archives, but did not find anything
>
> You might have to use a custom login shell.

If you just want to reduce them from whatever the system defaults are
you could just put the appropriate ulimit commands in the shell's
startup (probably /etc/profile).

--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev [at] mindrot
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev


michael.hebenstreit at intel

Aug 6, 2012, 8:38 AM

Post #4 of 4 (280 views)
Permalink
RE: FW: ulimits in ssh/sshd without resorting to PAM? [In reply to]

The problem is in a an HPC cluster - under normal circumstances lower limits are enforced, but some jobs need higher limits. We do not want to allow higher limits by default, except when explicitly requested by the users (because as default setting they are to high; a job not aware of correct limits might overload/crash the system).

Thanks for the answers; looks like my current method to set the limits in a start script and restart sshd is not so bad after all (even if it's clunky)

Happy hacking
Michael

-----Original Message-----
From: dtucker [at] dtucker [mailto:dtucker [at] dtucker] On Behalf Of Darren Tucker
Sent: Sunday, August 05, 2012 6:09 PM
To: Damien Miller
Cc: Hebenstreit, Michael; openssh-unix-dev [at] mindrot
Subject: Re: FW: ulimits in ssh/sshd without resorting to PAM?

On Mon, Aug 6, 2012 at 8:56 AM, Damien Miller <djm [at] mindrot> wrote:
> On Thu, 2 Aug 2012, Hebenstreit, Michael wrote:
>
>> Is there an (even rudimentary) way to compile/configure/use ulimits
>> in ssh/sshd without resorting to PAM?
>>
>> I've searched docs and archives, but did not find anything
>
> You might have to use a custom login shell.

If you just want to reduce them from whatever the system defaults are you could just put the appropriate ulimit commands in the shell's startup (probably /etc/profile).

--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev [at] mindrot
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

OpenSSH dev RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.