Xymon Mailing List Archive search

xymon ssh scan

list Chapman Flack
Fri, 11 Jun 2010 12:21:36 -0400
Message-Id: <user-dcd7efbe9d36@xymon.invalid>

On Fri, June 11, 2010 09:30, user-6b3be4007cf2@xymon.invalid wrote:
Just give the identity a login shell of /bin/true in /etc/passwd and you
won't have to be concerned about commands from a shell at all.
Yes, that works too, if you will create a new dedicated identity (or
reuse one that already has true for a shell).  command="/bin/true"
in authorized_keys will work in any event (though something like
/bin/echo OK might give a more positive confirmation).

The line in authorized_keys should also disallow all the extra
goodies like port forwarding, X tunneling, and so on.

-Chap