Re: (PerSource)Penalties default perhaps too aggressive?

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



> 
> I understand that the purpose of this script is to use the (one) working keypair(s) to "put the other ones on the server". How does it handle *that* objective in cases where it cannot observe the storage the pubkey is / may be in? And what behavior do you *want* in such a case?

What you are trying to do here (unless you are planning to code that, and I’ll be happy to beta test :)=) ) ioverengineering something, that (up till Dec’24 I believe) worked like a charm, but with the introduced (and I still believe it is over) aggressive rate limits, it fails unexpectedly for users.

As I’ve said elsewhere, I do understand the reason/case that is tried to protect, but I don’t yet see that as a valid concern in my logs up till now, and to make things less problematic, I’d rather advise on a less aggressive settings but still keep the feature in place. That way we’ll have less false positives.


_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev




[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux