Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-40790

[RFE] Support for authentication indicators in OpenSSH

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • openssh-9.9p1-11.el10
    • None
    • Moderate
    • FutureFeature
    • 2
    • rhel-security-crypto
    • ssg_security
    • 26
    • 0.5
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • Crypto25Q2, Crypto25July
    • Hide

      AC: When authentication indicators option is defined in sshd_config, the OpenSSH server reject any kerberos ticket that does not meet the specified indicators and the reason is correctly logged

      Show
      AC: When authentication indicators option is defined in sshd_config, the OpenSSH server reject any kerberos ticket that does not meet the specified indicators and the reason is correctly logged
    • Pass
    • Not Needed
    • New Test Coverage
    • Enhancement
    • Hide
      .OpenSSH server supports Kerberos authentication indicators

      When in Match configuration, OpenSSH server supports authentication indicators from Kerberos tickets. If the `GSSAPIIndicators` option is defined in `sshd` configuration, a Kerberos ticket that has indicators but does not match the policy is denied. If at least one indicator is configured, whether for access or denial, tickets without authentication indicators are explicitly rejected. For more information, see the `sshd_config(5)` man page on your system.
      Show
      .OpenSSH server supports Kerberos authentication indicators When in Match configuration, OpenSSH server supports authentication indicators from Kerberos tickets. If the `GSSAPIIndicators` option is defined in `sshd` configuration, a Kerberos ticket that has indicators but does not match the policy is denied. If at least one indicator is configured, whether for access or denial, tickets without authentication indicators are explicitly rejected. For more information, see the `sshd_config(5)` man page on your system.
    • Done
    • Done
    • Done
    • Unspecified
    • All
    • None

      We are starting to get requests for this feature due to the US Government OMB mandate M-22-09: (III.A.3) "When authorizing users to access resources, agencies must consider at least one device-level signal alongside identity information about the authenticated user".

       

      We are trying to enforce authentication indicators in Kerberos when using OpenSSH.

       

      I believe that https://github.com/openssh/openssh-portable/compare/master...abbra:openssh-portable:gssapi-indicators has already implemented this.

       

       

              dbelyavs@redhat.com Dmitry Belyavskiy
              rhn-support-mralph Mike Ralph
              Dmitry Belyavskiy Dmitry Belyavskiy
              Miluse Bezo Konecna Miluse Bezo Konecna
              Zuzana Fantini Zoubkova Zuzana Fantini Zoubkova
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: