| Summary: | ssh keeps asking for password even if there is permanent login failure | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Dalibor Pospíšil <dapospis> |
| Component: | openssh | Assignee: | Jakub Jelen <jjelen> |
| Status: | CLOSED NOTABUG | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | 7.3 | CC: | szidek |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-11-14 07:44:08 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Dalibor Pospíšil
2016-10-31 15:17:04 UTC
Hello Dalibor. It is not a bug. It is a (security) feature. You don't want to tell all the people on the internet that this account does not exists, does not have shell or does not have password. You want to behave the same way for all the accounts and not give any side channel information, which could be used against you. I don't want to close the bug with the first comment so I will give you some time to think about it, if it is clear from my explanation (if not, feel free to ask). But certainly, we are not going to change this behavior. |