[TriLUG] Re: OpenSSH Security Advisory (adv.iss)
Wed, 26 Jun 2002 15:25:33 -0400
On Wed, Jun 26, 2002 at 03:19:08PM -0400, Chris Merrill wrote:
> Just to make sure I've got this right, my config file says:
> #ChallengeResponseAuthentication yes
> but it doesn't say what default value is...and it's commented out.
> I don't think I've changed this value...so I assume this is the
> way it appears in the config at installation (RH 7.2).
> I think I should change this to:
> ChallengeResponseAuthentication no
If the line is commented out, then the default is whatever option was
selected at compile time. (In this case, most likely 'yes'). As you
thought, change it to 'no' and uncomment it.
This will not take effect until sshd is restarted. On a RedHat box you can
do this with:
Anything you can imagine (and many things you can't),
someone on the net is doing.
Brian Daniels firstname.lastname@example.org