Bug 2115610
| Summary: | SSHD option KbdInteractiveAuthentication cannot be directly set without ChallengeResponseAuthentication option | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Quynh Anh Pham <qpham> |
| Component: | openssh | Assignee: | Dmitry Belyavskiy <dbelyavs> |
| Status: | CLOSED WONTFIX | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.6 | CC: | jjelen, rlundgre |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-08-08 13:24:57 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Quynh Anh Pham
2022-08-05 02:15:27 UTC
Additional information supplied by the customer: When sshd_config has ChallengeResponseAuthentication set to yes and the PAM stack for sshd includes pam_env and pam_sss modules then any environment variables that the pam_env pam entries configure for the user shell do not get applied to the shell once authentication via sss completes. The setting of environment variables by sshd should not be controlled by the ChallengeResponseAuthentication setting. As documented in release notes, till OpenSSH 8.6 ChallengeResponseAuthentication was an option remaining from SSHv1, the KbdInteractiveAuthentication is newly defined in SSHv2 (RFC4256) and they were treated as somewhat but not entirely equivalent. Since OpenSSH 8.6+ (present in RHEL 9) ChallengeResponseAuthentication is an alias to KbdInteractiveAuthentication, so the fix you propose seems not worth implementing. |