how on earth does openssh not only have incredibly fucked versioning but is the only package i've ever seen to mention a "privilege separation" chroot path which actively breaks non-root builds. are you fucking kidding me bruh. "privilege separation chroot" defaulting to /var/empty and it immediately errors if it can't create it????? why are your version strings like that bruh?????
ok so they decided to reinvent sudo for sshd root https://github.com/openssh/openssh-portable/blob/master/README.privsep if i cannot disable the sshd build (reading ./configure --help in a crazed demented rage did not see the flag for it) i'm going to commit several murders
how do you spend 8kb of text and provide multiple detailed ASCII art diagrams regarding your privilege separation methodology and oh my god wait does it really require sshd to be root too yes it literally does are you fucking kidding me
this is so fucked
sshd is the main entry-point binary for the server. This binary retains privilege but performs a very limited set of tasks: loading and checking the configuration, listening for incoming connections
and monitoring the status of connections through the pre-authentication phase of their lifecycle to implement the MaxStartups and PerSourcePenalties features.
NONE OF THESE THINGS REQUIRE ROOT WHAT THE FUCK
@hipsterelectron Maybe I'm VASTLY missing the point here, but doesn't listening on port 22 require root, because 22 is a privileged port? Isn't there a tradition of servers being forced to use root on linux for this reason even if they don't need it for other reasons?
how is anyone ok with this????? it takes half the document and two fork/execs before it gets to why sshd-auth would need root:
All operations that require privilege, such as looking up user information, private key signatures, checking passwords, etc are performed by RPC to the parent sshd-session process.
- looking up user information????????
- i think you can calculate cryptographic signatures without root????
- the fuck do you mean """"checking passwords"""""
@hipsterelectron checking passwords for password auth requires reading /etc/shadow, which is restricted to root only
the private keys are stored under 600/rw------- perms by each user so other users can't read their keys. hence root is needed to access them
@hipsterelectron also listening for connections does require root since port 22 is root-only due to being <1024
@lunabee this is the least legitimate reason imho because you should be able to choose whatever port you want and furthermore any OS enforcing the 1024 port root rule is making users do a privilege escalation for absolutely no reason
@hipsterelectron yeah it's a known problem. legacy from back when people trusted sysadmins arbitrarily
but ssh isn't the kernel or posix standard so
they kinda need to
@lunabee IETF standards are more obviously backdoored than POSIX, which is less obviously backdoored than the kernel, and ssh -p selects an arbitrary port, as i am confident you are already aware. i do not remotely understand the "need" you are describing
@hipsterelectron changing user to the target user after login requires root