Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: SSHD with Secured authentication, using RSA PAM client |
|---|---|
| Date: | Fri, 3 Aug 2007 23:01:16 -0400 |
On 7/31/07, Edward Reiss <ed.reiss@convdata.com> wrote:
Greetings, Has anyone got ssh to authenticate to SecureID? We have to use the version of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
- You have make sure your sshd is pam enabled. ldd `which sshd` should have libpam in there. - man sshd_config. Depending on your sshd_config file you need enable either one of the two `UsePAM' or `PAMAuthenticationViaKBDInt' We enabled the radius daemon on our SecurID ACE server (RSA) and using pam_radius (of Freeradius) instead. If you choose that path you need to pick a radius secret key and need to add that key for your client on ACE database. Most of our servers using some flavor of ssh (openssh or sunssh or ssh) and pam_radius It basically prompts for Password: (you put your passcode here). We also have sudo with pam enabled. So there is no local password needed for users. These are files I needed to modify - /etc/raddb/server (only can access raddb dir) - /etc/pam.conf - just two extra lines; one for sshd and one for sudo - /etc/ssh/sshd_config OR /usr/local/etc/sshd_config
seems Solaris always tries to authenticate locally even after I configure
It has nothing to do with Solaris. It is SSHD that you need to configure right.
pam.conf. RSA has a "work around" but they do not support even the work around. RSA will support OpenSSH, but not the sshd included with Solaris.
The problem is not ssh difference. It is all handled by pam. Both SunSSH and OpenSSH knows how to communicate with PAM if they are compiled with pam library.
Any help would be appreciated. _______________________________ Edward Reiss <ed.reiss@convdata.com> Cell 631.681.7181 Landline 518.533.9764 Fax 631.881.5545 Quis custodiet ipsos custodes? _______________________________
-- Asif Iqbal PGP Key: 0xE62693C5 KeyServer: pgp.mit.edu
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: SSHD with Secured authentication, using RSA PAM client, Christian Lete Viesca |
|---|---|
| Next by Date: | RE: SSHD with Secured authentication, using RSA PAM client, Edward Reiss |
| Previous by Thread: | RE: SSHD with Secured authentication, using RSA PAM client, Edward Reiss |
| Next by Thread: | Check Point SmartCenter in Non-Global Zone, Crist J. Clark |
| Indexes: | [Date] [Thread] [Top] [All Lists] |