[1.7] Do the new security enhancements allow ssh under your own $USERNAME

View: New views
3 Messages — Rating Filter:   Alert me  

[1.7] Do the new security enhancements allow ssh under your own $USERNAME

by aputerguy :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

I read the materials in "What's New" and the section "Windows Security in Cygwin" with interest since it describes new authentication potentials.

However, I did not understand the material well enough to know whether 1.7 will allow users to ssh under their own $USERNAME or whether you will always get USERNAME=SYSTEM (assuming that you started sshd normally with cygrunsrv).

I use 'ssh' to log on to remote computers to initialize backups by setting up shadow mounts. However, since vshadow won't run as user SYSTEM, I have to go through crazy hoops using 'at' to launch the process at the next minute in the future so that I can get vshadow to run.

This ssh/security limitation is odd coming from a *nix environment where ssh gives you all the power you want or need...

Re: [1.7] Do the new security enhancements allow ssh under your own $USERNAME

by Larry Hall (Cygwin) :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On 11/05/2009 05:43 PM, aputerguy wrote:

>
> I read the materials in "What's New" and the section "Windows Security in
> Cygwin" with interest since it describes new authentication potentials.
>
> However, I did not understand the material well enough to know whether 1.7
> will allow users to ssh under their own $USERNAME or whether you will always
> get USERNAME=SYSTEM (assuming that you started sshd normally with
> cygrunsrv).
>
> I use 'ssh' to log on to remote computers to initialize backups by setting
> up shadow mounts. However, since vshadow won't run as user SYSTEM, I have to
> go through crazy hoops using 'at' to launch the process at the next minute
> in the future so that I can get vshadow to run.
>
> This ssh/security limitation is odd coming from a *nix environment where ssh
> gives you all the power you want or need...

Welcome to Windows! ;-)

I recommend that you try it and let us know if it solves your problem. The
intent
is to get Windows to understand the actual user with pubkey authentication.

--
Larry Hall                              http://www.rfk.com
RFK Partners, Inc.                      (508) 893-9779 - RFK Office
216 Dalton Rd.                          (508) 893-9889 - FAX
Holliston, MA 01746

_____________________________________________________________________

A: Yes.
 > Q: Are you sure?
 >> A: Because it reverses the logical flow of conversation.
 >>> Q: Why is top posting annoying in email?

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple


Re: [1.7] Do the new security enhancements allow ssh under your own $USERNAME

by Corinna Vinschen-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Nov  5 14:43, aputerguy wrote:
>
> I read the materials in "What's New" and the section "Windows Security in
> Cygwin" with interest since it describes new authentication potentials.
>
> However, I did not understand the material well enough to know whether 1.7
> will allow users to ssh under their own $USERNAME or whether you will always
> get USERNAME=SYSTEM (assuming that you started sshd normally with
> cygrunsrv).

Apparently you didn't read
http://cygwin.com/1.7/cygwin-ug-net/ntsec.html#ntsec-setuid-overview
close enough.  It's all there.


Corinna

--
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader          cygwin AT cygwin DOT com
Red Hat

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple