[Bug 501956] [NEW] OpenSSH does not log failed attempts when key authentication is used
Nygel Lyndley
ubuntu.com at lyndley.com
Thu Dec 31 18:59:19 GMT 2009
Public bug reported:
========================================================
Description: Ubuntu 9.10
Release: 9.10
openssh-server:
Installed: 1:5.1p1-6ubuntu2
Candidate: 1:5.1p1-6ubuntu2
Version table:
*** 1:5.1p1-6ubuntu2 0
500 http://us.archive.ubuntu.com karmic/main Packages
100 /var/lib/dpkg/status
========================================================
If you disable password authentication in sshd_config
(PasswordAuthentication no) and attempt to log in with an incorrect key,
a failed login attempt entry should appear in auth.log, as it does with
username/password authentication. Nothing is logged though.
If you change "LogLevel INFO" to "VERBOSE" in /etc/ssh/sshd_config you
do get an entry as below but it isn't enough to indicate a potential
issue :
"Dec 31 18:17:33 localhost sshd[8011]: Connection from 82.23.xx.yy port
38583"
** Affects: openssh (Ubuntu)
Importance: Undecided
Status: New
--
OpenSSH does not log failed attempts when key authentication is used
https://bugs.launchpad.net/bugs/501956
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to openssh in ubuntu.
More information about the Ubuntu-server-bugs
mailing list