data:image/s3,"s3://crabby-images/e954d/e954de18ff752ba43d5ee258ab7a28c9c6478c70" alt="Novell LINUX ENTERPRISE DESKTOP 11 Скачать руководство пользователя страница 180"
NOTE: File Permissions for Host-Based Authentication
If the host-based authentication is to be used, the file
/usr/lib/ssh/
ssh-keysign
or
/usr/lib64/ssh/ssh-keysign
should have setuid bit
set, which is not the defaut setting in SUSE Linux Enterprise Server. In such a
case, set the file permissions manually. You should use
/etc/permissions
.local
for this purpose, to make sure that the setuid bit is preserved after
security updates of openssh.
14.7 X, Authentication, and
Forwarding Mechanisms
Beyond the previously described security-related improvements, SSH also simplifies
the use of remote X applications. If you run
ssh
with the option
-X
, the
DISPLAY
variable is automatically set on the remote machine and all X output is exported to the
remote machine over the existing SSH connection. At the same time, X applications
started remotely and locally viewed with this method cannot be intercepted by unautho-
rized individuals.
By adding the option
-A
, the ssh-agent authentication mechanism is carried over to the
next machine. This way, you can work from different machines without having to enter
a password, but only if you have distributed your public key to the destination hosts
and properly saved it there.
Both mechanisms are deactivated in the default settings, but can be permanently acti-
vated at any time in the systemwide configuration file
/etc/ssh/sshd_config
or the user's
~/.ssh/config
.
ssh can also be used to redirect TCP/IP connections. In the examples below, SSH is
told to redirect the SMTP and the POP3 port, respectively:
ssh -L 25:sun:25 jupiter
With this command, any connection directed to jupiter port 25 (SMTP) is redirected to
the SMTP port on sun via an encrypted channel. This is especially useful for those using
SMTP servers without SMTP-AUTH or POP-before-SMTP features. From any arbitrary
location connected to a network, e-mail can be transferred to the “home” mail server
166
Security Guide
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......