Hey,
You're right, when a User is denied access via a Allow or Deny rule in sshd_config, the same error will be logged to the syslog.
But, it's actually a good practice to limit access to SSH with some Allow / Deny blocks in sshd_config to just some entitled users, like system maintainers.
The SSHD on the I offers no exit points to implement any kind of security besides standard os400 object/IFS permissions.
Hence in the default sshd configuration, any user with a valid "normal" user profile on your i can start an interactive shell via SSH and roam your filesystems, even when they are denied STRQSH via 5250.
See this post:
http://gmane.comp.hardware.ibm.midrange.narkive.com/V1tL8lcq/ssh-client-to-syslog-how-to-send#post1 for more on this topic.
Best Regards
Max
-----Original Message-----
From: OpenSource [mailto:opensource-bounces@xxxxxxxxxxxx] On Behalf Of Justin Taylor
Sent: Mittwoch, 28. März 2018 14:52
To: IBMi Open Source Roundtable
Subject: Re: [IBMiOSS] ssh i Access Solutions SSH client
Have you checked the config for allow/deny directives?
http://www-01.ibm.com/support/docview.wss?uid=nas8N1011847
-----Original Message-----
From: Bradley Stone [mailto:bvstone@xxxxxxxxx]
Sent: Tuesday, March 27, 2018 6:49 PM
To: IBMi Open Source Roundtable <opensource@xxxxxxxxxxxx>
Subject: [IBMiOSS] ssh i Access Solutions SSH client
I am trying to log into an SSH session with i Access Client solutions.
I was able to use another id no problem.
Using this new ID I get:
"Permission denied, please try again."
I know I'm using the right password.
Permission to what???? :)
--
This is the IBMi Open Source Roundtable (OpenSource) mailing list To post a message email: OpenSource@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options,
visit:
https://lists.midrange.com/mailman/listinfo/opensource
or email: OpenSource-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at
https://archive.midrange.com/opensource.
As an Amazon Associate we earn from qualifying purchases.