From mboxrd@z Thu Jan 1 00:00:00 1970 From: Christopher Allan Webber Subject: bug#26695: openssh password-authentication? should be #f by default Date: Fri, 28 Apr 2017 09:37:13 -0500 Message-ID: <87k264tx8m.fsf@dustycloud.org> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46646) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d4726-0003uX-OQ for bug-guix@gnu.org; Fri, 28 Apr 2017 10:38:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d4722-0003Bs-Qb for bug-guix@gnu.org; Fri, 28 Apr 2017 10:38:06 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:46637) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1d4722-0003Be-Mb for bug-guix@gnu.org; Fri, 28 Apr 2017 10:38:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1d4722-0007R1-HT for bug-guix@gnu.org; Fri, 28 Apr 2017 10:38:02 -0400 Sender: "Debbugs-submit" Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46406) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d471M-0003ru-Qh for bug-guix@gnu.org; Fri, 28 Apr 2017 10:37:21 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d471I-0002fj-Tm for bug-guix@gnu.org; Fri, 28 Apr 2017 10:37:20 -0400 Received: from dustycloud.org ([50.116.34.160]:60710) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1d471I-0002eZ-Og for bug-guix@gnu.org; Fri, 28 Apr 2017 10:37:16 -0400 Received: from oolong (localhost [127.0.0.1]) by dustycloud.org (Postfix) with ESMTPS id 1297D26632 for ; Fri, 28 Apr 2017 10:37:14 -0400 (EDT) List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: 26695@debbugs.gnu.org Our default permits password authentication for the openssh service (and the others it seems) by default in Guix. This is somewhat dangerous because this is a much easier to break in this way, and some users might not assume the default is reasonably safe. If users really want password-authentication, they should turn it on explicitly.