delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2017/03/21/21:34:51

X-Recipient: archive-cygwin AT delorie DOT com
DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:subject:message-id:mime-version
:content-type; q=dns; s=default; b=QaUixB5cj6FH4bMbMqmK3OAabKVRj
ei1CoEHiCWdXr0Pgr97WXhABXMC2e0lGfb+zjmOwZsx7ayT1/N9fdHzpAzAJXiDD
SgsRSfivqeqY7n/K5uFgeWQdzSQ08fl/ObtbAZMe4yBq2DGnulf13HB7BXAftSer
/sni+cYCb4G0Zs=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:subject:message-id:mime-version
:content-type; s=default; bh=wo//S2q00w0aGHKTLhYu70Ilh+w=; b=Ww2
VpPbIykr4u/iZ242QeHvEClfPFf0mdS2sTNNBoa51oWSEz9xqgWy5zJjKFjyECLo
jFEpnxTLSjnVu4VCVcsw6R4My2VNqngzXa/4mlV1IBIyv2TdZ0FFldDAzJeO7COr
PalG9fKm7JO1BV+TipLCY0QNIgrvI0YeLLbhltjg=
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Authentication-Results: sourceware.org; auth=none
X-Virus-Found: No
X-Spam-SWARE-Status: No, score=-25.4 required=5.0 tests=BAYES_00,FAKE_REPLY_C,GIT_PATCH_0,GIT_PATCH_1,GIT_PATCH_2,GIT_PATCH_3,RP_MATCHES_RCVD,SPF_PASS autolearn=ham version=3.3.2 spammy=typical, globally, 17677, privileges
X-HELO: mulm.lionel.fourquaux.org
Date: Wed, 22 Mar 2017 02:34:27 +0100
From: Lionel Fourquaux <lionel DOT fourquaux AT normalesup DOT org>
To: cygwin AT cygwin DOT com
Subject: Re: [ANNOUNCEMENT] Updated: OpenSSH-7.5p1-1
Message-ID: <20170322013427.GA6640@emris.lionel.fourquaux.org>
MIME-Version: 1.0
User-Agent: Mutt/1.8.0 (2017-02-23)

--azLHFNyN32YCQGCU
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

> * This release deprecates the sshd_config UsePrivilegeSeparation
>   option, thereby making privilege separation mandatory.

This has (probably not wholly intended) consequences when running sshd in=
=20
single user (non root) mode:

$ /usr/sbin/sshd -D -f ~/.ssh/sshd_config
Privilege separation user sshd does not exist

The problem is not limited to Cygwin, but is unlikely to happen in=20
a typical Unix, since ssh is probably installed globally.

If Cygwin was installed without administrative privileges, creating=20
a dedicated sshd user would be impossible (and makes little sense if sshd=
=20
runs in single user mode, anyway).  I guess it would be possible to add=20
a fake user account in /etc/passwd.

Since user sshd and chroot /var/empty are not used in single user mode,=20
it might be better to remove the check in this case:

=3D=3D=3D cut after =3D=3D=3D
diff --git a/sshd.c b/sshd.c
index 010a2c3..4f9b2c8 100644
--- a/sshd.c
+++ b/sshd.c
@@ -1641,7 +1641,8 @@ main(int ac, char **av)
=20
 	/* Store privilege separation user for later use if required. */
 	if ((privsep_pw =3D getpwnam(SSH_PRIVSEP_USER)) =3D=3D NULL) {
-		if (use_privsep || options.kerberos_authentication)
+		if ((use_privsep || options.kerberos_authentication)
+		    && (getuid() =3D=3D 0 || geteuid() =3D=3D 0))
 			fatal("Privilege separation user %s does not exist",
 			    SSH_PRIVSEP_USER);
 	} else {
@@ -1767,7 +1768,7 @@ main(int ac, char **av)
 		    key_type(key));
 	}
=20
-	if (use_privsep) {
+	if (use_privsep && (getuid() =3D=3D 0 || geteuid() =3D=3D 0)) {
 		struct stat st;
=20
 		if ((stat(_PATH_PRIVSEP_CHROOT_DIR, &st) =3D=3D -1) ||
=3D=3D=3D cut before =3D=3D=3D

Best regards,

		-- Lionel


--azLHFNyN32YCQGCU
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJY0dSjAAoJEHbPJVmwRuh6xc0QAImITJOei7sG3W+KGugVG/L2
3Gx67CJnnBWqYQhZLAgfL3dM9kXZQLgsdlhmZiUSdSFh9PC7DjIRxMBcl+jd55ON
XuHA2Rz3IvUOPeTN5j8sdSX+2Tv37Zv+gBm/E+fTHXFdxU1wYW7CnM0pdg6SB5PJ
xDjeS5LXXLIYqNRD5aGhh99EFgxQVfw/fVpNzQk1NrgG8DS3D24dpmBgHYmfOHUL
ficDNQmAR5S7TTSyCKsGLZPWVp6Ze4OqbVeWHDA9Iki1sGiwNE5b9KohuNDKrfF8
0TmT4/qqsw1mEABFLwlJsLbJBGFOara0gC0abKoi9ZQuVUOiisIMbHwIKl44veP6
08jU6vWa5L5btt/Ak7GcU8MTLAkKm1zcIHRg6YM7ct87ieR7zOcwmY4af7HJr0H1
dFLKx2rhBbhI/JQroOPElJc/5V9E/xs56Zl6SxlFrzUnTtnPogILKR9kJAhMSmVA
PLdHb409S9jViiWoefEofaqffJeIDI8I/UyBx+uyHlECYB93qhjJe4DZ+LOZxY6+
L192mN1L/euda4XSq7fHyMjsj39g8nsAGjUBjnOTKjItob/Ja4PzV9kF3estM7lR
g9FEhnxW3m5AMJYERgri1dSLlYOjKZ3jfMd2Rq62El4EDScIKuXCUhNtc1CW3CoV
k6dezGMdNi38cxVJU5W6
=1l5K
-----END PGP SIGNATURE-----

--azLHFNyN32YCQGCU--

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019