Re: external authentification
Torsten Bitterlich <[email protected]>
| Newsgroups | gmane.network.net-snmp.user |
|---|---|
| Organization | port GmbH |
| Message-ID | <[email protected]> |
Am Freitag 25 Juni 2010 15:52:40 schrieb Wes Hardaker: > >>>>> On Wed, 23 Jun 2010 08:42:22 +0200, Torsten Bitterlich <[email protected]> > >>>>> said: > Ok, I got it to the point where an SSH connection seems to be established. The user is authenticated. However following error happens: This is the debug log of sshd, though I don't know if there is any hint: debug1: SELinux support disabled debug1: PAM: establishing credentials debug1: permanently_set_uid: 1001/1001 debug1: Entering interactive session for SSH2. debug1: server_init_dispatch_20 User child is on pid 5137 debug1: server_input_channel_open: ctype session rchan 0 win 65536 max 16384 debug1: input_session_request debug1: channel 0: new [server-session] debug1: session_new: session 0 debug1: session_open: channel 0 debug1: session_open: session 0: link with channel 0 debug1: server_input_channel_open: confirm session debug1: server_input_channel_req: channel 0 request subsystem reply 1 debug1: session_by_channel: session 0 channel 0 debug1: session_input_channel_req: session 0 req subsystem subsystem request for snmp debug1: subsystem: exec() /usr/local/bin/sshtosnmp debug1: Received SIGCHLD. debug1: session_by_pid: pid 5138 debug1: session_exit_message: session 0 channel 0 pid 5138 debug1: session_exit_message: release channel 0 debug1: session_by_channel: session 0 channel 0 debug1: session_close_by_channel: channel 0 child 0 debug1: session_close: session 0 pid 0 debug1: channel 0: free: server-session, nchannels 1 Received disconnect from 127.0.0.1: 11: Normal Shutdown debug1: do_cleanup That is what snmpget complains about: snmpget -Y defSecurityModel=ksm -v 3 -l authPriv -u ben -A testtest -X homehome ssh:localhost:22 sysUpTime.0 netsnmp_ssh_send wasn't passed a valid tmStateReference snmpget: Unknown engine ID (Sub-id not found: (top) -> sysUpTime) If I enable debug logging I get the following statements: trace: usm_rgenerate_out_msg(): snmpusm.c, 1793: usm: USM processing completed. trace: _sess_async_send(): snmp_api.c, 5122: sess_process_packet: sending message id#535021286 reqid#1000021040 netsnmp_ssh_send wasn't passed a valid tmStateReference trace: snmpv3_engineID_probe(): snmp_api.c, 1440: snmp_api: unable to determine remote engine ID snmpget: Unknown engine ID (Sub-id not found: (top) -> sysUpTime) trace: netsnmp_ssh_close(): snmpSSHDomain.c, 451: ssh: close fd 3 Can you take anything out of this and give me a hint. Would be highly appreachiated! > - The whole system hasn't really been reviewed for safety and a double > check by someone else is really needed before it could be declared > "safe". > I really would like to do that. Maybe I can help testing and share my experience. -- with best regards / mit freundlichen Grüßen Torsten Bitterlich port - Professionals in Industrial Communication +=========================================================== | port GmbH phone +49 345 77755-0 | D-06132 Halle/Saale mailto:[email protected] | Germany http://www.port.de | CAN Wiki http://www.CAN-Wiki.info/ | Newsletter: http://www.port.de/subscribe +=========================================================== port Gesellschaft für computergestützte Automation mbH Geschäftsführer: Christian Bornschein, Heinz-Jürgen Oertel, Marcus Tangermann Sitz der Gesellschaft: Halle/Saale Registergericht Sachsen-Anhalt Stendal HRB 212667 ------------------------------------------------------------------------------ This SF.net email is sponsored by Sprint What will you do first with EVO, the first 4G phone? Visit sprint.com/first -- http://p.sf.net/sfu/sprint-com-first _______________________________________________ Net-snmp-users mailing list [email protected] Please see the following page to unsubscribe or change other options: https://lists.sourceforge.net/lists/listinfo/net-snmp-users