From owner-freebsd-security@FreeBSD.ORG Thu Oct 7 18:53:24 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9739A16A4CE for ; Thu, 7 Oct 2004 18:53:24 +0000 (GMT) Received: from yem.eng.utah.edu (yem.eng.utah.edu [155.99.222.96]) by mx1.FreeBSD.org (Postfix) with ESMTP id 81BD543D49 for ; Thu, 7 Oct 2004 18:53:24 +0000 (GMT) (envelope-from ogden@yem.eng.utah.edu) Received: from ogden by yem.eng.utah.edu with local (Exim 4.42 (FreeBSD)) id 1CFdPF-0006fH-PM; Thu, 07 Oct 2004 12:54:25 -0600 Date: Thu, 7 Oct 2004 12:54:25 -0600 From: Mark Ogden To: Mark Skurzynski Message-ID: <20041007185425.GB25539@yem.eng.utah.edu> Mail-Followup-To: Mark Skurzynski , freebsd-security@freebsd.org References: <20041007195417.430a8b5c@ariel.office.volker.de> <20041007180630.GA25130@yem.eng.utah.edu> <79722fad041007112227c3c241@mail.gmail.com> <20041007183400.GA25339@yem.eng.utah.edu> <3C735693-1890-11D9-B63E-000A95CD9660@uncompiled.com> <080b01c4ac9e$90584250$0a13a8c0@lomag.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <080b01c4ac9e$90584250$0a13a8c0@lomag.net> User-Agent: Mutt/1.5.5.1i Sender: Mark L Ogden cc: freebsd-security@freebsd.org Subject: Re: Question restricting ssh access for some users only X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 07 Oct 2004 18:53:24 -0000 Mark Skurzynski on Thu, Oct 07, 2004 at 02:50:49PM -0400 wrote: > Hi Fellow Marks, > > I normally don't reply here however the simple solution is to run a 2nd > instance of sshd on any random port you choose, ie. "sshd -f > /etc/ssh/sshd_config_private" or whatever you choose. You could then easily > firewall that port and only allow specific IP's to connnect. Yes, that was our second idea. But we feel theres got to be a better way. -Mark