• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Root login to SSH

Scheduled Pinned Locked Moved General pfSense Questions
6 Posts 3 Posters 15.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    anystupidassname
    last edited by Oct 20, 2006, 3:16 AM

    I've edited sshd_config to not allow root user to login and restarted the pfsense box (I'm BSD stupid so I couldn't figure out how to restart the ssh service) but I can still log in as root.  ??? Any advice would be much appreciated.

    1 Reply Last reply Reply Quote 0
    • D
      DanielSHaischt
      last edited by Oct 20, 2006, 3:56 AM

      There are two issues I see here:

      • #1) /etc/ssh/sshd_config gets re-generated from data that is stored in /conf/config.xml

      • #2) The way (config option) you are trying to prevent root logins is simply wrong

      Issue #1 means that your custom sshd_config gets overwritten. Please check whether /etc/ssh/sshd_config still contains your custom modification.

      Regards
      Daniel S. Haischt

      Mit freundlichen Gruessen / With kind regards
      DAn.I.El S. Haischt

      1 Reply Last reply Reply Quote 0
      • A
        anystupidassname
        last edited by Oct 21, 2006, 12:07 AM

        Thanks for the reply.

        1. sshd_config has not retained my configuration change as you suspected.
        2. please advise what change you would recommend instead.

        Thank you.

        1 Reply Last reply Reply Quote 0
        • D
          DanielSHaischt
          last edited by Oct 24, 2006, 2:58 PM

          This is a more general issue …

          The issue is that the current process expects that the user configures the system through the HTML based webGUI. This means that editing config files manually may cause an issue where your manually edited config file gets overwritten by the system sooner or later.

          Even SuSE's Yast had this issue...

          Upcoming pfSense releases may support user roles. This means you would be able to specify whether a user will have the right to login via SSH. Tho PermitRootLogin no isn't currently implemented (neither in RELENG/stable nor in HEAD/unstable).

          But this brings me to the question: Why are you going to disable root SSH-logins, if root and admin are the only shell users on a default 1.0 pfSense system?

          Regards
          Daniel S. Haischt

          Mit freundlichen Gruessen / With kind regards
          DAn.I.El S. Haischt

          1 Reply Last reply Reply Quote 0
          • S
            sai
            last edited by Oct 30, 2006, 12:16 PM

            You can disable ssh completely.

            Look in the Advanced menu (the very first menu option).

            There will be an option "Enable Secure Shell". Make sure that the tick box in empty.

            1 Reply Last reply Reply Quote 0
            • D
              DanielSHaischt
              last edited by Oct 31, 2006, 8:07 PM

              SSH is disabled by default anyway…

              Mit freundlichen Gruessen / With kind regards
              DAn.I.El S. Haischt

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received