Skip to main content
Question

"Secure SSH" combined with hidden local admin account broken?


donmontalvo
Forum|alt.badge.img+36

Is anyone else having a problem with using "Secure SSH" in conjunction with a hidden local admin account during imaging time?

Hiding the local admin account through JSS seems to result in a "broken" ACL for SSH...

http://donmontalvo.com/jamf/secure_ssh_hidden_admin_acct/Hidden_local_admin_acct_locked_out.jpg
http://donmontalvo.com/jamf/secure_ssh_hidden_admin_acct/Secure_SSH_feature_in_JSS_7.31.jpg
http://donmontalvo.com/jamf/secure_ssh_hidden_admin_acct/Sharing_SSH_settings.png

Thanks,
Don

11 replies

Forum|alt.badge.img+24
  • Valued Contributor
  • 1892 replies
  • August 4, 2010

Ensure your ssh account belongs to the group com.apple.access_ssh. Being a
hidden account, it won't show up in the GUI there in Sharing.  You need to
make sure it's there via dscl.
-- 
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436


Forum|alt.badge.img+11
  • Contributor
  • 415 replies
  • August 4, 2010

you can use Workgroup manager to make sure it is

Criss Myers
Senior Customer Support Analyst (Mac Services)
iPhone / iPad Developer
Apple Certified Technical Coordinator v10.5
LIS Development Team
Adelphi Building AB28
University of Central Lancashire
Preston PR1 2HE
Ex 5054
01772 895054


Forum|alt.badge.img+24
  • Valued Contributor
  • 1892 replies
  • August 4, 2010

pffft. Using the GUI is a sign of weakness.

;)
--
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436


Forum|alt.badge.img+11
  • Contributor
  • 415 replies
  • August 4, 2010

nah :-) make life easy for yaself :-)

Do you not use Casper Admin? thats a GUI :-)

Criss Myers
Senior Customer Support Analyst (Mac Services)
iPhone / iPad Developer
Apple Certified Technical Coordinator v10.5
LIS Development Team
Adelphi Building AB28
University of Central Lancashire
Preston PR1 2HE
Ex 5054
01772 895054


Forum|alt.badge.img+21
  • Contributor
  • 1028 replies
  • August 4, 2010

Actually, Jared writes everything to the db in mysql terminal...he’s that hardcore!

Craig E

On 8/4/10 8:39 AM, "Criss Myers" <cmyers at uclan.ac.uk> wrote:

nah :-) make life easy for yaself :-)

Do you not use Casper Admin? thats a GUI :-)

Criss Myers

Senior Customer Support Analyst (Mac Services)

iPhone / iPad Developer

Apple Certified Technical Coordinator v10.5

LIS Development Team

Adelphi Building AB28

University of Central Lancashire

Preston PR1 2HE

Ex 5054

01772 895054


Forum|alt.badge.img+24
  • Valued Contributor
  • 1892 replies
  • August 4, 2010

Afterall, the Matrix is best seen in its native form…
--
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436


Forum|alt.badge.img+31
  • Honored Contributor
  • 2721 replies
  • August 4, 2010

How was this account created? If remote log in is enabled I am almost certain the user can ssh. Unless you set it to certain users specifically

Also command line is always faster and once you get the commands down you can then proceed to achieve automation.


donmontalvo
Forum|alt.badge.img+36
  • Author
  • Hall of Fame
  • 4293 replies
  • August 4, 2010

Tom, Craig, Jared, Criss...thanks for all your responses. After some troubleshooting with John Miller (welcome to JAMF, John!), we found the issue.

Diagnosis: brain f at rt. I had the admin name spelled wrong.

I'm so ashamed....if anyone needs me, I'll be in purgatory.

Don


donmontalvo
Forum|alt.badge.img+36
  • Author
  • Hall of Fame
  • 4293 replies
  • August 4, 2010

Tom, Craig, Jared, Criss...thanks for all your responses. After some troubleshooting with John Miller (welcome to JAMF, John!), we found the issue.

Diagnosis: brain fart. I had the admin name spelled wrong.

I'm so ashamed....if anyone needs me, I'll be in purgatory.

Don


Forum|alt.badge.img+12
  • Contributor
  • 312 replies
  • August 5, 2010

:D Awesome…. lol :D ;)

Ryan M. Manly
Glenbrook High Schools


Forum|alt.badge.img+31
  • Honored Contributor
  • 2721 replies
  • August 5, 2010

All Wizards have beards, including Unix wizards :) *strokes beard
while writing this email*


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings