delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2023/08/17/17:12:00

X-Recipient: archive-cygwin AT delorie DOT com
DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org BA9193853D05
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cygwin.com;
s=default; t=1692306719;
bh=1DajvIsc0G4KVrl43KFmtyEUnGVTJrfbHhWhifqWZL4=;
h=To:Subject:Date:List-Id:List-Unsubscribe:List-Archive:List-Post:
List-Help:List-Subscribe:From:Reply-To:From;
b=opJMFTAo1bMGbC+9Vek03OCOSRkmwQ1rbn5/p13xeKjbe8+n1uaxm0DqrbUrvVhUL
gmTzm6uPWx1jAGaQbXfXvxWmoX5T8DqGm22tyQRmgvuXUoYTUSBfn7IFtPnRUO+wQ3
UuZwBw/fHWogyWCaurSsK7S+sIHSrFFwVl1R4+Co=
X-Original-To: cygwin AT cygwin DOT com
Delivered-To: cygwin AT cygwin DOT com
DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org E65013858D20
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=anXusuyM8WySfKq98l9GeFmH7QY9T6sViVxid8YMh6nAn6IkMoMuY2LlXy2sVH3+BQnXRRQY0vheUnzucLOaZsdKzWMwzkBfZjuzvYp4P9acvUP1lDKK59llx2Gkyq66v+k6mFqhfe6GmN3bCO/Ywl/x8LkTt2KCs6p2D2nw8xHXyw/6n5iraXjM4957Veuk0/ljUiB4YLLS1o88DeNcF8rbo2SweKkxG3NeinwFZkgl+U1QEpeIQeyH+Q9p+2ymnpusKlcq/UtM68Wbs2Ri16Kly0KnZMdkc9FYEflyoZhkdoVbOOehj9iIo2jD4Ls/oJGIb8VVXhqPqcJHFyHrtw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=+XAX6J0kFymuDhgj5RyjHz8m5DR+1WW+jD11p0bB/iY=;
b=X0jNxURE0iNs+ydZA1TO5397mQo0nisqyL93KFv6953aUYnPa0a+IkpFvqPRmZp4+W3YoxaSHyvsG9CCeGr9igLhZmQ/GF+4CbEQAPVgNIro6bvEGQ5VNV2OzVkTR+GctMUNukcdN3UAOrh/kGlh9lTONntId2lFsCxi85Jkqjvn83AkrAftwDjzhu2MeWqwO+I/lW0eGeOfy9izw3666n2qdCwH24Pz/bbSuAOMs/+T4FCBlpN7x1dWxC5zlcJCmXbo/hBx9u74w/7ZIwCkCeQD0QM1UQZM3IiHE6unEXZ5x70fA5f4DOym/Of6HIY/Ng/qOsHGyNIXHs3uk8tTNw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
smtp.mailfrom=bryanhealth.org; dmarc=pass action=none
header.from=bryanhealth.org; dkim=pass header.d=bryanhealth.org; arc=none
To: "cygwin AT cygwin DOT com" <cygwin AT cygwin DOT com>
Subject: Cygwin openssh AllowGroups
Thread-Topic: Cygwin openssh AllowGroups
Thread-Index: AdnRTZNVTfcR86urTE2+7ha6wYBdUw==
Date: Thu, 17 Aug 2023 21:11:18 +0000
Message-ID: <PH0PR16MB4782893F3EA5CBEC4408F37DF51AA@PH0PR16MB4782.namprd16.prod.outlook.com>
Accept-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR16MB4782:EE_|SA2PR16MB4236:EE_
x-ms-office365-filtering-correlation-id: 95b81051-2a82-413a-51fd-08db9f667fd9
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: UTzERHZyaFGHyeXzeuKsg0X+zACF8pO6/5EwSUv9cxGdFeljAVUtmIXlwp/aJM9Vrx/3LyaLvdwvwfUe+84EbQwnZsWSOAWnbJyV1NftwkfuXDjFd79U7a/d72QRuSzQgQIXk+sseSlbro9KoCcAAubCfjlSeHR9nAcLBdmwTcQE6iJ6RP4s0xXkxmQSGZzFQnCImqgE5N1i2XezjGB30KcFBpTzeuZodk2LeympDg925ADyvQm3msglDWAIAAdjmUtS9L1T4spgYEdl4EO9zsLgLHg/pQY4/oY9bDWeco070VY4vlklSrNpp/tgqeXEetenBrMjaVyCJNLAld7/UySIcM0qQkwQLnEGrCuR/qNARMfqmmcJghDLjGHmB500FuR8XiBLKMi0KUNxwm9RntR29iV6pmfpxXr1ebrK2rGJ9sQLVtHngRQYd06Cs4jyQePQCRitsSzMYe9SVC+1mYgQc5TO+WxWzBnpNNCMIDLgUGdQxIKDQgmSECBhXSODJHcoZALqAUJltimeFwQkC/jj3XU+HQfvCcrp2TvpGpytqQzjhl9N3sQMJXtBzPoSZvYaGPVmXTSalu0dUa9n+YHmEaJRE4Q0gwc67HVjSaSi6O1TQ3UaofUV6FUs4byZ
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:PH0PR16MB4782.namprd16.prod.outlook.com; PTR:; CAT:NONE;
SFS:(13230031)(136003)(39850400004)(376002)(366004)(346002)(396003)(1800799009)(451199024)(186009)(55016003)(83380400001)(66476007)(38100700002)(38070700005)(66556008)(66446008)(66946007)(316002)(6916009)(64756008)(122000001)(478600001)(76116006)(45080400002)(2906002)(41300700001)(7116003)(52536014)(5660300002)(8676002)(8936002)(3480700007)(9686003)(7696005)(6506007)(71200400001)(26005)(86362001)(33656002);
DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?us-ascii?Q?6jVks/3Fz6jd1/9bL3VHtgkeiX9Q5Ni+a3R/2LR/6Fa8atCYH3QYIyrq0T4+?=
=?us-ascii?Q?+akyBDds3VNkCkk2gdsU6TqNrUJ5tkwEexmocyVA/du7NoVP8miEQbB93EUe?=
=?us-ascii?Q?MoX7WRp3uXXkTTwQmFfKNix/qS2hCa0fImxAb7/SyPVA7VPKFYRL4fDsnQqi?=
=?us-ascii?Q?dWQONJQHflTFyDd4BiXBTSMl7CKAN0/hNyeaq7YcBlWMBbZ2/UToDotjGYEu?=
=?us-ascii?Q?1YrneB4ZXDn/SYkEydup4UgvJhnZ2GmSv/lPRm+E9bsR/PeybrMtnJCU2LEt?=
=?us-ascii?Q?uN8R05aj0Ng2jrjLvLJEIrNFQYg+8kii59XQAazUSGgVMm7SHA9JguMxFKZn?=
=?us-ascii?Q?e4OFr14EkTn02O0UtDjo2ggDLuSIT3TvEiZtch9oZnFd/dvndQfWGrS/tmgd?=
=?us-ascii?Q?EMcAc4Ir10erT0wz5JuAMEVF36JSPdjRybtsTZVJ8MSKWk9XoHhqSIvkB5W2?=
=?us-ascii?Q?F77LNYCxpb8HRM4CC9/eCENnP/jRQFxjDFT2U8CcSbXe3vixbvADwLL6SFIu?=
=?us-ascii?Q?+N0x8KwwIP1jBYn+PbkQI1/GPqsQoojFzRoLOnO+IH43OLjCmmoUMSfBxbSQ?=
=?us-ascii?Q?UpV8qOgu0vVSnkoMWMs17YBH/ndNbQ0nna3kjW0zSHC8NNanagOTPEjTjK6k?=
=?us-ascii?Q?s+xpTYcKwKLhUQqKKerrTMGSrsOtUQvApB1W0VvmeeCtbm5yH9x9BnHZveEt?=
=?us-ascii?Q?4zjzzHFjdLLDYPvn9S7zz9OmMqHZk9QR8Esk0c5qFoQP+TPuZSVgYyW81OTC?=
=?us-ascii?Q?UO8FTbh2h0gqE62UywHI7xKwc5DxvBb5w/quosM1KozWL74HunPdhJ8+CRWw?=
=?us-ascii?Q?JR7gAB3FKfVDjk49kUiVbsOY+f4CIC9cf/3xnP0Q8+G+IWBfsanxabHj0lcF?=
=?us-ascii?Q?xu4IodAzIv7+NAGCjgym5VuhXoth9kODxSQiABSbevzGr4w06rFKhbCS3L0M?=
=?us-ascii?Q?8bSaGauBvmU7Z/95cLlfmhhOXAlM25BjiJOebP6Yi6pG5bJxzW5p9BOCuCMm?=
=?us-ascii?Q?UNfawcHbxvfb976HL6unhlpp6PWKDHDxlL5K7KCa/76vSi8Krllc2qdip+Hh?=
=?us-ascii?Q?gYbfiZHddlbFpEWgvLefAtZkEDAt36j+74ZwtU2hYWsNrUJm3RudW8TWhQf8?=
=?us-ascii?Q?5blgDL01EtZZSlOsG+uxFxXjaJ7X62z5B5FfYB9U8n+gD4elkLiMqz2EL7to?=
=?us-ascii?Q?5Vm9pKe2d5+g7ZGVXRnN121+Xw3HwVH7DwR8YThQfxdITm7KJlKaTk2dIq8q?=
=?us-ascii?Q?/nP5vKS0ZQlJh4E3Din97erhI2OxRTNBdJgEJb3iiqSsXupIuKHlC2fiturd?=
=?us-ascii?Q?HwM6yKrrnh9BlXVfKLM0XoMKPkf2qTnIVjWK3DcaT9Aw6C+sKT2dX2L1Q5kh?=
=?us-ascii?Q?cLHqLgmGaluLGkprR9uoIXFsaFU0t6KrWE4Fpl8r/BDTEwNwHTdHJp8Md9y6?=
=?us-ascii?Q?OBdCHkk9xHf0bSCc0JWUvIHY2SOpBeKTgdOCI/P5YauMptvMeQh9WcM8zs7v?=
=?us-ascii?Q?gxZKyYfPexLsQ7HiTVULsqKGT10Jn1/nCcjdt/jbaIYXC2ZsO+BiiDBCXFyA?=
=?us-ascii?Q?cyKKVV+dUVYYzj/9X2DZWgEEv9Mi604Mz9+dJ2yz?=
MIME-Version: 1.0
X-OriginatorOrg: bryanhealth.org
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR16MB4782.namprd16.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 95b81051-2a82-413a-51fd-08db9f667fd9
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Aug 2023 21:11:18.2925 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 09b11d70-e37c-4120-b532-c13f0e4aa18f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: lTXu5HEd5Cvut4fojgUZu3D8ZuX2WKAqtCPo5YDrAgwF05E5WTY4p12AFqTo+iLFsbmmO8vBoYFgrKAk1Iylyg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA2PR16MB4236
X-Proofpoint-GUID: fYM3LgNcd43fYx-D-WgDHsZnd-75OfzQ
X-Proofpoint-ORIG-GUID: fYM3LgNcd43fYx-D-WgDHsZnd-75OfzQ
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0
priorityscore=1501
adultscore=0 lowpriorityscore=0 impostorscore=0 bulkscore=0 mlxscore=0
clxscore=1011 phishscore=0 spamscore=0 suspectscore=0 mlxlogscore=567
malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1
engine=8.19.0-2306200000 definitions=main-2308170190
X-Spam-Status: No, score=-0.2 required=5.0 tests=BAYES_00, DKIM_SIGNED,
DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, LIKELY_SPAM_FROM, SPF_HELO_NONE,
SPF_PASS, TXREP autolearn=no autolearn_force=no version=3.4.6
X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on
server2.sourceware.org
X-BeenThere: cygwin AT cygwin DOT com
X-Mailman-Version: 2.1.29
List-Id: General Cygwin discussions and problem reports <cygwin.cygwin.com>
List-Archive: <https://cygwin.com/pipermail/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-request AT cygwin DOT com?subject=help>
List-Subscribe: <https://cygwin.com/mailman/listinfo/cygwin>,
<mailto:cygwin-request AT cygwin DOT com?subject=subscribe>
From: Dale Lobb via Cygwin <cygwin AT cygwin DOT com>
Reply-To: Dale Lobb <Dale DOT Lobb AT bryanhealth DOT org>
Sender: "Cygwin" <cygwin-bounces+archive-cygwin=delorie DOT com AT cygwin DOT com>

  Is there a known issue in Cygwin's implementation of openssh in the AllowGroups clause of sshd_config?  I cannot get it to work.

  I have a domain member server where I want to limit ssh logins to just members of a few groups.  Without those limits, any domain user can log into the server.  The AllowGroups clause of sshd_config appears tailor made for this purpose.,  But it does not work with either local groups or domains groups specified.  The AllowUsers clause works as documented, but listing out all the possible users would be tedious at best.

  I've searched back through the Cygwin archives, and there was a fair amount of chatter about this very issue 15 years ago or more, but none of the posts mention a general solution, other than to create a /etc/passwd file and list the group as the user's primary group.  But we aren't using /etc/passwd and /etc/group in Cygwin any more.  And even if that is the solution, it just moves the maintenance of the list from sshd_config to the passwd file.

  Anyone know how to get openssh AllowGroups to work in a more generic way like it does on a  true Linux system?

  Or am I barking up the wrong tree and no one uses Cygwin's openssh anymore?  I saw a recent post to this mailing list where the questioner was told to install Microsoft's distribution of openssh.

Best Regards,

Dale



________________________________

CONFIDENTIALITY NOTICE: This e-mail message, including any attachments, is for the sole use of the intended recipients and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply e-mail and destroy all copies of the original message.

-- 
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019