2 ms·
Ah, you're right. I read sshd_config(5) on Arch, which uses 6.9p1 and says the incorrect default is "no". I assumed this was the case on other distros. So to c
by anonova 11y ago
Ah, you're right. I read sshd_config(5) on Arch, which uses 6.9p1 and says the incorrect default is "no". I assumed this was the case on other distros.
So to correct my previous post (I can't seem to edit?), it should be, "Debian-based distros set `without-password`, and others use the default `yes`."
Thanks for the correction!
- scintill76 11y agoThanks for the reply. On editing, I'm not sure exactly how it works, but posts on HN become uneditable at some point. I came across this post[1] and bug comment[2]. If I'm understanding correctly, Red Hat will not follow the OpenBSD upstream on this! So I would guess CentOS and Fedora will also keep allowing root login, with password, by default. [1] https://lists.fedoraproject.org/pipermail/package-announce/2015-July/161692.html https://lists.fedoraproject.org/pipermail/package-announce/2... [2] https://bugzilla.redhat.com/show_bug.cgi?id=89216#c26 https://bugzilla.redhat.com/show_bug.cgi?id=89216#c26