PermitRootLogin

Bug #45416 reported by Matti Lindell
62
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssh (Ubuntu)
Invalid
Wishlist
Unassigned

Bug Description

To increase security and somewhat follow conventions described on
https://wiki.ubuntu.com/RootSudo

/etc/ssh/sshd_config
PermitRootLogin should be set to false by default.

Revision history for this message
Colin Watson (cjwatson) wrote :

This has been discussed many times before and rejected. Note that this is also the upstream default. PermitRootLogin allows you to have an audit trail of public keys used to log in to the root account rather than having to figure out which account escalated to root; furthermore on a system where the root password is enabled, it is appropriate to log in directly since otherwise the account you use to escalate to root is essentially root-equivalent. In Ubuntu's default configuration, it makes no difference whether PermitRootLogin is enabled or not, so the comments in RootSudo do not apply here.

Changed in openssh:
status: Unconfirmed → Rejected
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.