www.delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2009/02/18/11:36:09

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=-2.4 required=5.0 tests=AWL,BAYES_00,SPF_HELO_PASS
X-Spam-Check-By: sourceware.org
Message-ID: <499C384F.2070708@cygwin.com>
Date: Wed, 18 Feb 2009 11:33:19 -0500
From: "Larry Hall (Cygwin)" <reply-to-list-only-lh AT cygwin DOT com>
Reply-To: cygwin AT cygwin DOT com
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.19) Gecko/20090101 Remi/2.0.0.19-1.fc8.remi Lightning/0.9 Thunderbird/2.0.0.19 Mnenhy/0.7.5.0
MIME-Version: 1.0
To: cygwin AT cygwin DOT com
Subject: Re: sshd w/o admin?
References: <c4e763ac0902172203k559a0f3dg99af0d680edc4431 AT mail DOT gmail DOT com>
In-Reply-To: <c4e763ac0902172203k559a0f3dg99af0d680edc4431@mail.gmail.com>
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Aaron Davies wrote:
> is it possible to get sshd working w/o admin privs?

Running 'ssh-host-config' requires adminstrative privileges to create
users to run 'sshd' as a service (for W2K3 and later) and for privilege
separation.  If you don't want/need these, then you can bypass these
as part of the configuration.  This will mean:

   1. You cannot run sshd as a service (on W2K3 or later) so you will not
      be able to use pub-key authentication.  On W2K and XP systems, you
      can use the existing 'SYSTEM' user to run 'sshd' as a service if
      you'd like.

   2. You will always be running 'sshd' as a "privileged" user but this
      doesn't mean much if you're not running it as a user with elevated
      privileges, which you're likely not if you chose not to run as a
      service, this is likely a non-issue.

> i've run ssh-host-config (without creating a new user) and started
> sshd manually from the shell.
> 
> when i try to connect, i get "Connection closed by 127.0.0.1" and an
> error "sshd: PID 6520: fatal: seteuid 45758: Permission denied" shows
> up in the event viewer
> 
> "id" idnicates that 45758 is me
> 
> any suggestions?

Use password authentication?

If you need to follow-up on this thread, please read and follow the problem
reporting guidelines found here - <http://cygwin.com/problems.html>

-- 
Larry Hall                              http://www.rfk.com
RFK Partners, Inc.                      (508) 893-9779 - RFK Office
216 Dalton Rd.                          (508) 893-9889 - FAX
Holliston, MA 01746

_____________________________________________________________________

A: Yes.
 > Q: Are you sure?
 >> A: Because it reverses the logical flow of conversation.
 >>> Q: Why is top posting annoying in email?

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019