Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-17385

"UsePAM no" is commented out, which is misleading since default is "UsePAM yes"

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Minor Minor
    • None
    • rhel-9.3.0
    • openssh
    • None
    • Moderate
    • rhel-security-crypto
    • ssg_security
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • All
    • None

      What were you trying to do that didn't work?

      Checking default /etc/ssh/sshd_config file, I can see the following comment:

      # Set this to 'yes' to enable PAM authentication, account processing,
      # and session processing. If this is enabled, PAM authentication will
      # be allowed through the KbdInteractiveAuthentication and
      # PasswordAuthentication.  Depending on your PAM configuration,
      # PAM authentication via KbdInteractiveAuthentication may bypass
      # the setting of "PermitRootLogin without-password".
      # If you just want the PAM account and session checks to run without
      # PAM authentication, then enable this but set PasswordAuthentication
      # and KbdInteractiveAuthentication to 'no'.
      # WARNING: 'UsePAM no' is not supported in RHEL and may cause several
      # problems.
      #UsePAM no
      

      The "#UsePAM no" is misleading, this makes the admin believe the default is no, hence the default configuration we ship uses an unsupported setting.
      "#UsePAM yes" should be displayed instead.

      Please provide the package NVR for which bug is seen:

      openssh-server-8.7p1-34.el9.x86_64

      How reproducible:

      Always

      Steps to reproduce

      1.  Install a RHEL9.3 system with default profile

        Expected results

        #UsePAM yes
        

        Actual results

        #UsePAM no
        

              dbelyavs@redhat.com Dmitry Belyavskiy
              rhn-support-rmetrich Renaud Métrich
              Dmitry Belyavskiy Dmitry Belyavskiy
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: