Mailinglist Archive: opensuse-factory (626 mails)

< Previous Next >
Re: [opensuse-factory] request for comments: disable ssh daemon by default
  • From: Oddball <monkey9@xxxxxx>
  • Date: Fri, 28 Mar 2008 19:37:11 +0100
  • Message-id: <47ED3AD7.5080101@xxxxxx>
Richard (MQ) schreef:
Arvin Schnell wrote:
On Fri, Mar 28, 2008 at 03:28:59PM +0100, Marcus Meissner wrote:
Hi,

We are thinking about disabling the ssh daemon by default.

Reason is that it most desktop users do not use it all
and it is just taking away memory for those, and also
presenting an attack surface once the firewall is disabled.

Why not combine it with the firewall setting?

IIRC there is already the option to open the SSH port in the
network setup during installation so simply start sshd when the
port is opened there.

+1

Users who use ssh will in general know about the firewall etc. too, others probably shouldn't have it enabled.

Having said that - surely the memory footprint must be fairly small, and ssh security bugs are fairly rare ! ;-)


Or make an extra item in the network setup for SSH just like for
VNC (or combine those two).

Combining them makes sense - my argument above applies here too.



As i am not mistaken, this is already so.
As i don't use the firewall, because my Lan is unaccessible when it is on, i turn it off when concluding the install.
When i do that, ssh closes.

--

Enjoy your time around,


Oddball (Now or never...)


Besturingssysteem: Linux 2.6.25-rc5-git2-5-default x86_64
Current user: oddball@AMD64x2-sfn1
System: openSUSE 11.0 (x86_64) Alpha3
KDE: 4.00.66 (KDE 4.0.66 >= 20080313) "release 6.1"

---------------------------------------------------------------------
To unsubscribe, e-mail: opensuse-factory+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-factory+help@xxxxxxxxxxxx

< Previous Next >