SSL Contrib Programs

rsh

The code for rsh is in the directory security/rsh. This is the 4.4BSD version of rsh, with modifications to compile on various unix machines, and support for SSL and socks added. Several arguments have been added to support the new features. The syntax for the command line is:

rsh [-n] [-d] [-l login] host [command]
rsh [-n] [-d] -S secargs [-K certdir] [-k nickname] [-l login] host [command]

The -n flag indicates that rsh should not process any input.

The -d flag turns on some debugging.

The -S flag sets the security parameters. The secargs string should be two character long. If the first character is 'e' then encryption is enabled. Any other value of the first character will turn off encryption. If the second character is 'p' then a socks proxy is used. Any other value of the second character will disable socks and attempt to use a direct connection. NOTE: If you are using socks then you should have the environment variable SOCKS_HOST set to the name of your socks proxy machine.

The -K flag specifies the location of the key and certificate databases as the certdir directory. Without this flag, the default is /usr/etc/ssl, unless the environment variable SSL_DIR has been set to override this default.

The -k flag enables client authentication. If the server requests client authentication, the nickname string will be used to access the client's key and certificate. The user will then be prompted for a password for the key. The key and certificate databases will be read from the default directory, unless otherwise specified (see above).

The -l flag logs you into the remote host as login rather than the current local username.

host is the hostname or address of the machine to connect to and execute command.

If encryption is enabled then rsh will attempt to connect to the port for a service named "shells". If encryption is not being used then it will connect to the standard "shell" port. If you want to use encryption then you should add a line to /etc/services specifying a port for the "shells" service.

If you don't enable encryption or socks use via -S then this rsh acts like the normal bsd version of rsh.

rsh needs to be suid root, or be run as root.

rshd

The code for rshd is in security/rshd. This is the 4.4BSD version or rshd with a few modifications so that it can be run from ssld. This version of rshd does not do SSL directly, but rather it expects to be run by ssld. It uses the ssld control socket to create the stderr connection back to the client application.

WARNING: This version of rshd has its reserved port checking disabled. This enables use of secure rsh through a socks proxy, but it bypasses one of the traditional security measures of unix based networking. This is probably not much of a loss given how easy it is to get around today, but it may introduce a security hole if things are not configured correctly. It is strongly recomended that you configure ssld to use an access control list to ensure that only trusted people can access your system via rshd.

A sample line from the ssld configuration file to enable rshd might look like this:

#Port	Mode	      ACL        Key	  Cert	  Action
445	auth-server   rsh.acl    NAME     NAME	  exec ./rshd rshd
Notice that this configuration requires client authentication and has an access control list. Both are highly recommended.

rdist

The code for rdist is in security/rdist. This is the 6.1.0 version of rdist from USC. The original is available for anonymous ftp from usc.edu. This version has been modified to take some extra security arguments and to prompt the user for a password, which is passed to the SSL version of rsh. The new arguments are -k, -K, and -S, which are just passed through to rsh. If you don't specify any of these arguments then rdist uses the operating system's version of rsh and should behave like the un-modified rdist.

The default pathname for secure rsh is /usr/etc/ssl/srsh. You can override this with the -P option in rdist.

The version of rdistd included here has not been modified. It is included here for completeness. If you already have the current version of rdistd installed on the target system then you do not need to install this version.

WARNING: Since this version of rdist uses secure rsh, the same security considerations mentioned for rsh and rshd apply to rdist.