Am 21.12.18 um 11:04 schrieb Michael Hirmke:
AFAIK reicht das seit einiger Zeit nicht mehr, wenn UsePAM aktiviert ist. "UsePAM yes" overrided "PermitRootLogin yes". Zumindest bei mir hier war/ist das so. Auf allen meinen 'SUSE'n ist immer beides aktiv, wie sollte UsePAM denn PermitRootLogin 'overriden' ? Das sind grundverschiedene Dinge. PermitRootLogin:
Specifies whether root can log in using ssh(1). The argument must be yes, prohibit-password, without-password, forced-commands-only, or no. The default is yes. If this option is set to prohibit-password or without-password, password and keyboard-interactive authentication are disabled for root. If this option is set to forced-commands-only, root login with public key authentication will be allowed, but only if the command option has been speci- fied (which may be useful for taking remote backups even if root login is nor- mally not allowed). All other authentication methods are disabled for root. If this option is set to no, root is not allowed to log in. UsePAM Enables the Pluggable Authentication Module interface. If set to yes this will enable PAM authentication using ChallengeResponseAuthentication and PasswordAuthentication in addition to PAM account and session module processing for all authentication types. Because PAM challenge-response authentication usually serves an equivalent role to password authentication, you should disable either PasswordAuthentication or ChallengeResponseAuthentication. If UsePAM is enabled, you will not be able to run sshd(8) as a non-root user. The default is no. Frohe Weihnachten -- Christian ------------------------------------------------------------ https://join.worldcommunitygrid.org?recruiterId=177038 ------------------------------------------------------------ http://www.sc24.de - Sportbekleidung ------------------------------------------------------------ -- Um die Liste abzubestellen, schicken Sie eine Mail an: opensuse-de+unsubscribe@opensuse.org Um den Listen Administrator zu erreichen, schicken Sie eine Mail an: opensuse-de+owner@opensuse.org