Bug 613627

Summary: the patch for distribution authozed keys should be updated
Product: Red Hat Enterprise Linux 6 Reporter: Jan F. Chadima <jchadima>
Component: opensshAssignee: Tomas Mraz <tmraz>
Status: CLOSED CURRENTRELEASE QA Contact: Miroslav Vadkerti <mvadkert>
Severity: high Docs Contact:
Priority: high    
Version: 6.0CC: ebenes, mvadkert, sgrubb, tmraz
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openssh-5.3p1-19.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-11-10 21:17:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan F. Chadima 2010-07-12 13:07:42 UTC
Description of problem:
the patch enabling distribution of the aythorized keys should be updated to be compatible with the upstream version.

Comment 1 Tomas Mraz 2010-07-12 13:19:45 UTC
The patch as is currently included in RHEL-6 openssh package has some minor security weaknessess - not vulnerabilities per se but the administrator might create insecure configurations with it.

Comment 6 Miroslav Vadkerti 2010-08-12 10:17:40 UTC
VERIFIED as fixed in openssh-5.3p1-19.el6

NEW PACKAGE - openssh-5.3p1-19.el6
:: [   PASS   ] :: File '/etc/ssh/sshd_config' should contain 'AuthorizedKeysCommand'
:: [   PASS   ] :: File '/etc/ssh/sshd_config' should contain 'AuthorizedKeysCommandRunAs'
:: [   PASS   ] :: RESULT: Test

OLD PACKAGE - openssh-5.3p1-18.el6
:: [   FAIL   ] :: File '/etc/ssh/sshd_config' should contain 'AuthorizedKeysCommand' 
:: [   FAIL   ] :: File '/etc/ssh/sshd_config' should contain 'AuthorizedKeysCommandRunAs' 
:: [   FAIL   ] :: RESULT: Test

Comment 7 releng-rhel@redhat.com 2010-11-10 21:17:06 UTC
Red Hat Enterprise Linux 6.0 is now available and should resolve
the problem described in this bug report. This report is therefore being closed
with a resolution of CURRENTRELEASE. You may reopen this bug report if the
solution does not work for you.