Forum Discussion
How to configure ChallengeResponseAuthentication no
Dear Sir or Madam
I configure the BIG-IP.
I want to disable ChallengeResponseAuthentication.
I find /var/run/config/sshd_config file.
" Excerpt from cat /var/run/config/sshd_config "
THIS IS AN AUTO-GENERATED FILE -- DO NOT EDIT!!!
ChallengeResponseAuthentication yes
I want to configure ChallengeResponseAuthentication no.
How to configure ChallengeResponseAuthentication no.
I'm afraid my expressions may be rude or hard to read, because I'm not so good at English.
Yours faithfully
2 Replies
- Shaun_Simmons1
Altostratus
Do you want to change it to "no" because of:
"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.
And
"Note that if ChallengeResponseAuthentication is 'yes', and the PAM authentication policy for sshd includes pam_unix(8), password authentication will be allowed through the challenge-response mechanism regardless of the value of PasswordAuthentication."
??
- Shaun_Simmons1
Altostratus
Looks like you are safe and do not have to change ChallengeResponseAuthentication yes to "no"
According to: https://support.f5.com/kb/en-us/solutions/public/9000/100/sol9107.html
*Did you null out the line by typing "" if not, the challenge is not used.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com