Rakhesh Sasidharan wrote:
> Any ideas or nudges in the right direction as to why this is happening?
> Looks like I've understood the interaction between SSH and PAM wrong
> here, so would appreciate some enlightenment.

According to my understanding of the SSH protocol, you're continually
asked because an authentication failure is not a fatal error.

When authenticating an SSH session, a list of mutually supported methods
is compiled (public-key, challenge-response, S/Key,
keyboard-interactive, plaintext) and the client cycles through the list
based on what it thinks is most likely to work.

It's perfectly acceptable for a client to attempt password
authentication before public-key, or even interleave them. All the
server can do is say yay or nay to an attempt with a restricted method,
because it cannot know if the next attempt may utilize an allowed method.

After the requisite three or five failed attempts (depending on the
server config), it may send a general failure code (too many failed
attempts) and disconnect the client at it's discretion.

Fuzzy love,
Technical Administrator
CyberLeo.Net Webhosting

Furry Peace! - http://wwww.fur.com/peace/
freebsd-questions@freebsd.org mailing list
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to