Re: problem with HostbasedAuthentication
Mahmood Naderan <[email protected]> Thu, 28 Apr 2011 10:42:42 -0700 (PDT)
| Newsgroups | gmane.network.openssh.general |
|---|---|
| Message-ID | <[email protected]> |
Dear Sharad,=0AI am now trying to setup a hostbased ssh from server to clie= nt (previously client->server worked fine based on your help). I want it to= be bidirectional.=0A=A0=0AI did the same thing in reverse (now the client = becomes server and the server becoms client). However this is what I get wh= ile trying to ssh from server to client:=0A=A0=0A=A0=0Adebug3: Wrote 48 byt= es for a total of 1063=0Adebug2: service_accept: ssh-userauth=0Adebug1: SSH= 2_MSG_SERVICE_ACCEPT received=0Adebug2: key: /home/mahmood/.ssh/identity ((= nil))=0Adebug2: key: /home/mahmood/.ssh/id_rsa ((nil))=0Adebug2: key: /home= /mahmood/.ssh/id_dsa ((nil))=0Adebug3: Wrote 64 bytes for a total of 1127= =0Adebug1: Authentications that can continue: publickey,password,hostbased= =0Adebug3: start over, passed a different list publickey,password,hostbased= =0Adebug3: preferred gssapi-keyex,gssapi-with-mic,gssapi,hostbased,publicke= y,keyboard-interactive,password=0Adebug3: authmethod_lookup hostbased=0Adeb= ug3: remaining preferred: publickey,keyboard-interactive,password=0Adebug3:= authmethod_is_enabled hostbased=0Adebug1: Next authentication method: host= based=0Aget_socket_address: getnameinfo 8 failed: Name or service not known= =0Adebug2: userauth_hostbased: chost server.=0Adebug2: ssh_keysign called= =0Adebug3: ssh_msg_send: type 2=0Adebug3: ssh_msg_recv entering=0Adebug1: p= ermanently_drop_suid: 1000=0Aget_socket_address: getnameinfo 8 failed: Name= or service not known=0Acannot get sockname for fd=0Assh_keysign: no reply= =0Akey_sign failed=0Adebug2: we did not send a packet, disable method=0Adeb= ug3: authmethod_lookup publickey=0Adebug3: remaining preferred: keyboard-in= teractive,password=0Adebug3: authmethod_is_enabled publickey=0Adebug1: Next= authentication method: publickey=0Adebug1: Trying private key: /home/mahmo= od/.ssh/identity=0Adebug3: no such identity: /home/mahmood/.ssh/identity=0A= debug1: Trying private key: /home/mahmood/.ssh/id_rsa=0Adebug3: no such ide= ntity: /home/mahmood/.ssh/id_rsa=0Adebug1: Trying private key: /home/mahmoo= d/.ssh/id_dsa=0Adebug3: no such identity: /home/mahmood/.ssh/id_dsa=0Adebug= 2: we did not send a packet, disable method=0Adebug3: authmethod_lookup pas= sword=0Adebug3: remaining preferred: ,password=0Adebug3: authmethod_is_enab= led password=0Adebug1: Next authentication method: [email protected]= 68.1.3's password:=0A=0A=A0=0AWhat is your suggestion?=0A=0A// Naderan *Mah= mood;=0A=0A=0A----- Original Message -----=0AFrom: Sharad <sharad2011@yahoo= .com>=0ATo: Mahmood Naderan <[email protected]>=0ACc: "secureshell@secur= ityfocus.com" <[email protected]>=0ASent: Thursday, April 28, 2= 011 5:20 PM=0ASubject: Re: problem with HostbasedAuthentication=0A=0AMahmoo= d, =0A=0AThe files are /home/username/.ssh/known_hosts on both server and c= lient.=0A=0ABy FQDN, I meant host's fully qualified domain name. =0A=0AFoll= owing is the example:=0A=0AAssuming both client and server are linux hosts:= =0A=0AServer IP: 192.168.1.1=0AClient IP: 192.168.1.101=0A=0AServer Name: l= nx_srvr_1.domain.com=0AClient Name: lnx_clnt_101.domain.com=0A=0AUser name = on each host is mahmood.=0A=0AFollowing would be the entries in .shosts on = lnx_srvr_1=0A=0A=0Alnx_srvr_1:/home/mahmood $ cat .shosts=0A=0Alnx_clnt_101= .domain.com mahmood=0A192.168.1.101 mahmood=0Alnx_clnt_101 mahmood=0A=0AFol= lowing should exist in /home/mahmood/.ssh/known_hosts file on the server si= de:=0A192.168.1.101,lnx_clnt_101,lnx_clnt_101.domain.com=A0 ssh-rsa AAAAB3N= z...=0A=0AFollowing should also exist in /home/mahmood/.ssh/known_hosts fil= e on the client side:=0A192.168.1.1,lnx_srvr_1,lnx_srvr_1.domain.com=A0 ssh= -rsa AAAAB3Nz...=0A=0AEnsure that .ssh directory on both client and server = are rwx for owner only and group/rest of world is 000.=0A=0AHope this helps= ! Good Luck! :)=0A=0ARegards,=0ASharad=A0 =0A--- On Thu, 28/4/11, Mahmood N= aderan <[email protected]> wrote:=0A=0A> From: Mahmood Naderan <nt_mahmo= [email protected]>=0A> Subject: Re: problem with HostbasedAuthentication=0A> To:= "Sharad" <[email protected]>=0A> Cc: "[email protected]" <s= [email protected]>=0A> Date: Thursday, 28 April, 2011, 3:54 PM= =0A> Can you explain exactly which file I=0A> should edit? What is FQDN? By= 'hostname', Do you mean server=0A> hostname of client hostname. =0A> Shoul= d I do that on both side or server side?...=0A> =0A> // Naderan *Mahmood;= =0A> =0A> =0A> ----- Original Message -----=0A> From: Sharad <sharad2011@ya= hoo.com>=0A> To: Mahmood Naderan <[email protected]>;=0A> Asif Iqbal <va= [email protected]>=0A> Cc: "[email protected]"=0A> <secureshell@se= curityfocus.com>=0A> Sent: Thursday, April 28, 2011 1:16 PM=0A> Subject: Re= : problem with HostbasedAuthentication=0A> =0A> Sometimes the issue lies wi= th hostname as well. What I mean=0A> with that is the known_hosts may have = just the host name=0A> where as when the connection is established, the deb= ug shows=0A> the FQDN. I faced this issue so to be sure, I edited the=0A> k= nown_hosts file and inserted the hostname, hostname's FQDN=0A> and it's IP = address (all comma separated).=0A> =0A> Also ensure that you both the hosts= ' known_hosts files have=0A> opposite servers names (as prescribed above). = =0A> =0A> All the above checks makes it work for me.=0A> =0A> Hope this sol= ves.=0A> =0A> Kind regards,=0A> Sharad=0A> --- On Thu, 28/4/11, Asif Iqbal = <[email protected]>=0A> wrote:=0A> =0A> > From: Asif Iqbal <[email protected]= >=0A> > Subject: Re: problem with HostbasedAuthentication=0A> > To: "Mahmoo= d Naderan" <[email protected]>=0A> > Cc: "[email protected]"= =0A> <[email protected]>=0A> > Date: Thursday, 28 April, 2011, = 12:38 AM=0A> > On Wed, Apr 27, 2011 at 1:12 AM,=0A> > Mahmood Naderan <nt_m= [email protected]>=0A> > wrote:=0A> > >>Change the order method. Have hostba= sed=0A> before=0A> > password=0A> > >=0A> > > Sorry where should I do that?= =0A> > =0A> > man ssh_config and look into PreferredAuthentications=0A> > = =0A> > >=0A> > > // Naderan *Mahmood;=0A> > >=0A> > > From: Asif Iqbal <vad= [email protected]>=0A> > > To: Mahmood Naderan <[email protected]>=0A> > > C= c: "[email protected]"=0A> > <[email protected]>=0A= > > > Sent: Wednesday, April 27, 2011 9:17 AM=0A> > > Subject: Re: problem = with=0A> HostbasedAuthentication=0A> > >=0A> > >=0A> > > Change the order m= ethod. Have hostbased before=0A> > password=0A> > > On Apr 26, 2011 11:52 P= M, "Mahmood Naderan"=0A> <[email protected]>=0A> > wrote:=0A> > >>=0A> >= >>=0A> > >> Hi,=0A> > >> I am trying to setup a hostbased passwrodless=0A>= ssh=0A> > from a client to a server using this guide http://www.ehow.com/h= ow_7621307_set-up-hostbased-authentication.html.=0A> > >>=0A> > >> The clie= nt looks like:=0A> > >>=0A> > >> mahmood@client:~$ cat /etc/ssh/ssh_config= =A0 |=0A> grep=0A> > "HostbasedAuthentication"=0A> > >> =A0=A0 HostbasedAut= hentication yes=0A> > >> mahmood@client:~$ cat /etc/ssh/ssh_config=A0 |=0A>= grep=0A> > "EnableSSHKeysign"=0A> > >> =A0=A0 EnableSSHKeysign yes=0A> > >= >=0A> > >>=0A> > >> and the server looks like:=0A> > >> mahmood@server:~$ c= at /etc/ssh/sshd_config=A0=0A> |=0A> > grep "HostbasedAuthentication"=0A> >= >> HostbasedAuthentication yes=0A> > >> mahmood@server:~$ cat /etc/ssh/ssh= d_config=A0=0A> |=0A> > grep "IgnoreRhosts"=0A> > >> IgnoreRhosts no=0A> > = >>=0A> > >> also the server has the key for client:=0A> > >>=0A> > >> mahmo= od@server:~$ cat=0A> /etc/ssh/ssh_known_hosts=0A> > >> client ssh-rsa AAAAB= 3Nz.....=0A> > >>=0A> > >> the ~/.shosts file on the server contains:=0A> >= >> mahmood@server:~$ cat .shosts=0A> > >> client.domain mahmood=0A> > >>= =0A> > >> Then on both server and client, the ssh=0A> service is=0A> > rest= arted:=0A> > >> mahmood@client:~$ sudo service ssh restart=0A> > >> ssh sta= rt/running, process 1355=0A> > >> mahmood@server:~$ sudo service ssh restar= t=0A> > >> ssh start/running, process 28982=0A> > >>=0A> > >> How, when I r= un "ssh -vvv server" from client=0A> (to=0A> > show the verbose messages), = I still get the password=0A> > prompt.=0A> > >>=0A> > >> mahmood@client:~$ = ssh -vvv server=0A> > >> OpenSSH_5.3p1 Debian-3ubuntu6, OpenSSL 0.9.8k=0A> = 25=0A> > Mar 2009=0A> > >> debug1: Reading configuration data=0A> > /etc/ss= h/ssh_config=0A> > >> debug1: Applying options for *=0A> > >> debug2: ssh_c= onnect: needpriv 0=0A> > >> debug1: Connecting to server [192.168.1.1]=0A> = port=0A> > 22.=0A> > >> debug1: Connection established.=0A> > >> debug1: id= entity file=0A> /home/mahmood/.ssh/identity=0A> > type -1=0A> > >> debug1: = identity file=0A> /home/mahmood/.ssh/id_rsa=0A> > type -1=0A> > >> debug1: = identity file=0A> /home/mahmood/.ssh/id_dsa=0A> > type -1=0A> > >> debug1: = Remote protocol version 2.0, remote=0A> > software version OpenSSH_5.3p1 De= bian-3ubuntu4=0A> > >> debug1: match: OpenSSH_5.3p1 Debian-3ubuntu4=0A> pat= =0A> > OpenSSH*=0A> > >> debug1: Enabling compatibility mode for=0A> protoc= ol=0A> > 2.0=0A> > >> debug1: Local version string=0A> SSH-2.0-OpenSSH_5.3p= 1=0A> > Debian-3ubuntu6=0A> > >> debug2: fd 3 setting O_NONBLOCK=0A> > >> d= ebug1: SSH2_MSG_KEXINIT sent=0A> > >> debug3: Wrote 792 bytes for a total o= f 831=0A> > >> debug1: SSH2_MSG_KEXINIT received=0A> > >> debug2: kex_parse= _kexinit:=0A> >=0A> diffie-hellman-group-exchange-sha256,diffie-hellman-gro= up-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-=0A> > >> group= 1-sha1=0A> > >> debug2: kex_parse_kexinit: ssh-rsa,ssh-dss=0A> > >> debug2:= kex_parse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,a= rcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > >> cbc= ,aes256-cbc,arcfour,[email protected]=0A> > >> debug2: kex_parse_= kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,a= es128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > >> cbc,aes256-cbc= ,arcfour,[email protected]=0A> > >> debug2: kex_parse_kexinit:=0A= > hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripemd160@open= ssh.com,hmac-sha1-96,hmac-=0A> > >> md5-96=0A> > >> debug2: kex_parse_kexin= it:=0A> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripemd16= [email protected],hmac-sha1-96,hmac-=0A> > >> md5-96=0A> > >> debug2: kex_parse= _kexinit: none,[email protected],zlib=0A> > >> debug2: kex_parse_kexinit: no= ne,[email protected],zlib=0A> > >> debug2: kex_parse_kexinit:=0A> > >> debug= 2: kex_parse_kexinit:=0A> > >> debug2: kex_parse_kexinit: first_kex_follows= =0A> 0=0A> > >> debug2: kex_parse_kexinit: reserved 0=0A> > >> debug2: kex_= parse_kexinit:=0A> >=0A> diffie-hellman-group-exchange-sha256,diffie-hellma= n-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-=0A> > >> = group1-sha1=0A> > >> debug2: kex_parse_kexinit: ssh-rsa,ssh-dss=0A> > >> de= bug2: kex_parse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour= 256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > >= > cbc,aes256-cbc,arcfour,[email protected]=0A> > >> debug2: kex_p= arse_kexinit:=0A> >=0A> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour= 128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-=0A> > >> cbc,aes25= 6-cbc,arcfour,[email protected]=0A> > >> debug2: kex_parse_kexini= t:=0A> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-ripemd160= @openssh.com,hmac-sha1-96,hmac-=0A> > >> md5-96=0A> > >> debug2: kex_parse_= kexinit:=0A> hmac-md5,hmac-sha1,[email protected],hmac-ripemd160,hmac-rip= [email protected],hmac-sha1-96,hmac-=0A> > >> md5-96=0A> > >> debug2: kex_= parse_kexinit: none,[email protected]=0A> > >> debug2: kex_parse_kexinit: no= ne,[email protected]=0A> > >> debug2: kex_parse_kexinit:=0A> > >> debug2: ke= x_parse_kexinit:=0A> > >> debug2: kex_parse_kexinit: first_kex_follows=0A> = 0=0A> > >> debug2: kex_parse_kexinit: reserved 0=0A> > >> debug2: mac_setup= : found hmac-md5=0A> > >> debug1: kex: server->client aes128-ctr=0A> hmac-m= d5=0A> > none=0A> > >> debug2: mac_setup: found hmac-md5=0A> > >> debug1: k= ex: client->server aes128-ctr=0A> hmac-md5=0A> > none=0A> > >> debug1:=0A> = > SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192)=0A> sent=0A> > >> debug1: exp= ecting SSH2_MSG_KEX_DH_GEX_GROUP=0A> > >> debug3: Wrote 24 bytes for a tota= l of 855=0A> > >> debug2: dh_gen_key: priv key bits set:=0A> 124/256=0A> > = >> debug2: bits set: 507/1024=0A> > >> debug1: SSH2_MSG_KEX_DH_GEX_INIT sen= t=0A> > >> debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY=0A> > >> debug3: Wro= te 144 bytes for a total of 999=0A> > >> debug3: check_host_in_hostfile: fi= lename=0A> > /home/mahmood/.ssh/known_hosts=0A> > >> debug3: check_host_in_= hostfile: match line 1=0A> > >> debug3: check_host_in_hostfile: filename=0A= > > /home/mahmood/.ssh/known_hosts=0A> > >> debug3: check_host_in_hostfile:= match line 2=0A> > >> debug1: Host 'server' is known and matches=0A> the R= SA=0A> > host key.=0A> > >> debug1: Found key in=0A> > /home/mahmood/.ssh/k= nown_hosts:1=0A> > >> debug2: bits set: 503/1024=0A> > >> debug1: ssh_rsa_v= erify: signature correct=0A> > >> debug2: kex_derive_keys=0A> > >> debug2: = set_newkeys: mode 1=0A> > >> debug1: SSH2_MSG_NEWKEYS sent=0A> > >> debug1:= expecting SSH2_MSG_NEWKEYS=0A> > >> debug3: Wrote 16 bytes for a total of = 1015=0A> > >> debug2: set_newkeys: mode 0=0A> > >> debug1: SSH2_MSG_NEWKEYS= received=0A> > >> debug1: SSH2_MSG_SERVICE_REQUEST sent=0A> > >> debug3: W= rote 48 bytes for a total of 1063=0A> > >> debug2: service_accept: ssh-user= auth=0A> > >> debug1: SSH2_MSG_SERVICE_ACCEPT received=0A> > >> debug2: key= : /home/mahmood/.ssh/identity=0A> ((nil))=0A> > >> debug2: key: /home/mahmo= od/.ssh/id_rsa=0A> ((nil))=0A> > >> debug2: key: /home/mahmood/.ssh/id_dsa= =0A> ((nil))=0A> > >> debug3: Wrote 64 bytes for a total of 1127=0A> > >> d= ebug1: Authentications that can continue:=0A> > publickey,password,hostbase= d=0A> > >> debug3: start over, passed a different list=0A> > publickey,pass= word,hostbased=0A> > >> debug3: preferred=0A> >=0A> gssapi-keyex,gssapi-wit= h-mic,gssapi,hostbased,publickey,keyboard-interactive,password=0A> > >> deb= ug3: authmethod_lookup hostbased=0A> > >> debug3: remaining preferred:=0A> = > publickey,keyboard-interactive,password=0A> > >> debug3: authmethod_is_en= abled hostbased=0A> > >> debug1: Next authentication method:=0A> hostbased= =0A> > >> debug2: userauth_hostbased: chost client.=0A> > >> debug2: ssh_ke= ysign called=0A> > >> debug3: ssh_msg_send: type 2=0A> > >> debug3: ssh_msg= _recv entering=0A> > >> debug1: permanently_drop_suid: 1000=0A> > >> debug2= : we sent a hostbased packet, wait for=0A> > reply=0A> > >> debug3: Wrote 6= 08 bytes for a total of 1735=0A> > >> debug1: Authentications that can cont= inue:=0A> > publickey,password,hostbased=0A> > >> debug2: userauth_hostbase= d: chost client.=0A> > >> debug2: ssh_keysign called=0A> > >> debug3: ssh_m= sg_send: type 2=0A> > >> debug3: ssh_msg_recv entering=0A> > >> debug1: per= manently_drop_suid: 1000=0A> > >> debug2: we sent a hostbased packet, wait = for=0A> > reply=0A> > >> debug3: Wrote 672 bytes for a total of 2407=0A> > = >> debug1: Authentications that can continue:=0A> > publickey,password,host= based=0A> > >> debug1: No more client hostkeys for=0A> hostbased=0A> > auth= entication.=0A> > >> debug2: we did not send a packet, disable=0A> method= =0A> > >> debug3: authmethod_lookup publickey=0A> > >> debug3: remaining pr= eferred:=0A> > keyboard-interactive,password=0A> > >> debug3: authmethod_is= _enabled publickey=0A> > >> debug1: Next authentication method:=0A> publick= ey=0A> > >> debug1: Trying private key:=0A> > /home/mahmood/.ssh/identity= =0A> > >> debug3: no such identity:=0A> > /home/mahmood/.ssh/identity=0A> >= >> debug1: Trying private key:=0A> > /home/mahmood/.ssh/id_rsa=0A> > >> de= bug3: no such identity:=0A> > /home/mahmood/.ssh/id_rsa=0A> > >> debug1: Tr= ying private key:=0A> > /home/mahmood/.ssh/id_dsa=0A> > >> debug3: no such = identity:=0A> > /home/mahmood/.ssh/id_dsa=0A> > >> debug2: we did not send = a packet, disable=0A> method=0A> > >> debug3: authmethod_lookup password=0A= > > >> debug3: remaining preferred: ,password=0A> > >> debug3: authmethod_i= s_enabled password=0A> > >> debug1: Next authentication method: password=0A= > > >> mahmood@server's password:=0A> > >>=0A> > >>=0A> > >> Any idea about= that?=0A> > >>=0A> > >> // Naderan *Mahmood;=0A> > >>=0A> > >=0A> > =0A> >= =0A> > =0A> > -- =0A> > Asif Iqbal=0A> > PGP Key: 0xE62693C5 KeyServer: pg= p.mit.edu=0A> > A: Because it messes up the order in which people=0A> norma= lly=0A> > read text.=0A> > Q: Why is top-posting such a bad thing?=0A> >=0A= >=0A