From Bugzilla Helper: User-Agent: Mozilla/4.61 [en] (WinNT; I) Description of problem: the in.rshd man page (/usr/share/man/man8/in.rshd.8.gz) which is part of the rsh-0.17-2.5.src.rpm states that: 8. Rshd then validates the user using ruserok(3), which uses the file /etc/hosts.equiv and the .rhosts file found in the user's home di- rectory. The -l option prevents ruserok(3) from doing any validation based on the user's ``.rhosts'' file (unless the user is the supe- ruser and the -h option is used.) If the -h option is not used, su- peruser accounts may not be accessed via this service at all. This no longer seems to be the case, when I invoke in.rshd via the xinetd daemon with the -h option the following is placed in /var/log/messages Jan 29 14:50:22 XXXXXXXX rshd[18576]: -l and -h functionality has been moved to pam_rhosts_auth in /etc/pam.conf Which is also not completely correct as the file in question is not /etc/pam.conf but /etc/pam.d/rsh. Version-Release number of selected component (if applicable): How reproducible: Always Steps to Reproduce: 1. install rsh-server rpm rsh-server-0.17-2.5 2. 'man rshd' or 'man in.rshd' Actual Results: man page displayed incorrect information regarding -h option for rshd in section 8. Expected Results: man page should display information concerning pam.d with regard to root rsh access. Perhaps something like 8. Rshd then validates the user using ruserok(3), which uses the file /etc/hosts.equiv and the .rhosts file found in the user's home di- rectory. The -l and -h options have been superceded by settings in the /etc/pam.d/rsh file. Superuser access may not be accessed without modifying this file and the /etc/securetty file as neccessary. Although I may be incorrect in this as the ruserok call may have been removed entirely in favor of a PAM based verification. Additional info:
Will check and update accordingly. Read ya, Phil
Fix will appear in new release.