Re: WRT FAQ: slow logins
Janne Johansson <[email protected]>
| Newsgroups | gmane.os.openbsd.www |
|---|---|
| Message-ID | <[email protected]> |
2010/11/24 Karsten M. Self <[email protected]> > > This feels all weird to me. First of all, openssh doesnt ship with > > GSSAPIAuthentication enabled by default, > > I don't recall if this was enabled by default or if I'd enabled it for > some specific reason (I don't recall that I did). And there's enough > wonkiness going on with our DNS at work that reverse lookups are a > pretty likely suspect. > > That said: disabling GSSAPIAuthentication at the command line or in > user or host configs fixes the problem. Pretty convincingly, and for > multiple users. > > > secondly if you actually use krb5 and enable GSSAPI it does not in itself > > cause any 30 second timeouts > > unless you have something broken, like reverse DNS mappings, which still > > makes the FAQ suggestion apply. > > > > If your site needs/uses GSSAPI, then removing "kerberized ssh from the > > $PATH" or taking out GSSAPI from the > > local ssh_config is definately not the correct solution and only hides > the > > symptoms of a broken site. > > The site doesn't use/need GSSAPI. Disabling the option results in no > functionality loss and far faster session set-up. > Any suggestions on further isolating DNS as the culprit? > > Yes. Check if you can resolve the ips for the client, the server you are ssh-ing into and the KDC, which you would need to have, if you enable GSSAPI. Chances are ssh is trying to resolve kerberos.your.domain.com or the SRV records for it. Then again, if you actually aren't using any GSSAPI at all, the fault is "enabling GSSAPI" of course, since kerberos needs a trusted third party and if you have none, its not an error if ssh/sshd is spending time trying to resolve default names for a KDC to .. "help" you get the tickets it has been asked to use when you enabled GSSAPI. -- To our sweethearts and wives. May they never meet. -- 19th century toast