ssh problems

From: rich lott (rl3_at_shinyblue.net)
Date: 09/22/04

  • Next message: Andreas Janssen: "Re: How to match kernel_headers and kernel versions?"
    To: debian-user@lists.debian.org
    Date: Wed, 22 Sep 2004 16:23:56 +0100
    
    

    I have a Woody box running ssh. I can remotely access it no problems using
    linux, but try from WinSCP and I can only log in as root! For other users it
    won't authenticate the password.

    Any ideas?

    sshd_config file is below.

    # Package generated configuration file
    # See the sshd(8) manpage for defails

    # What ports, IPs and protocols we listen for
    Port 22
    Port 22922
    # Use these options to restrict which interfaces/protocols sshd will bind to
    #ListenAddress ::
    #ListenAddress 0.0.0.0
    Protocol 2
    # HostKeys for protocol version 2
    HostKey /etc/ssh/ssh_host_rsa_key
    HostKey /etc/ssh/ssh_host_dsa_key
    #Privilege Separation is turned on for security
    UsePrivilegeSeparation yes

    # ...but breaks Pam auth via kbdint, so we have to turn it off
    # Use PAM authentication via keyboard-interactive so PAM modules can
    # properly interface with the user (off due to PrivSep)
    PAMAuthenticationViaKbdInt no
    # Lifetime and size of ephemeral version 1 server key
    KeyRegenerationInterval 3600
    ServerKeyBits 768

    # Logging
    SyslogFacility AUTH
    LogLevel INFO

    # Authentication:
    LoginGraceTime 600
    PermitRootLogin yes
    StrictModes yes

    RSAAuthentication yes
    PubkeyAuthentication yes
    #AuthorizedKeysFile %h/.ssh/authorized_keys

    # rhosts authentication should not be used
    RhostsAuthentication no
    # Don't read the user's ~/.rhosts and ~/.shosts files
    IgnoreRhosts yes
    # For this to work you will also need host keys in /etc/ssh_known_hosts
    RhostsRSAAuthentication no
    # similar for protocol version 2
    HostbasedAuthentication no
    # Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
    #IgnoreUserKnownHosts yes

    # To enable empty passwords, change to yes (NOT RECOMMENDED)
    PermitEmptyPasswords no

    # Uncomment to disable s/key passwords
    #ChallengeResponseAuthentication no

    # To disable tunneled clear text passwords, change to no here!
    PasswordAuthentication yes

    # To change Kerberos options
    #KerberosAuthentication no
    #KerberosOrLocalPasswd yes
    #AFSTokenPassing no
    #KerberosTicketCleanup no

    # Kerberos TGT Passing does only work with the AFS kaserver
    #KerberosTgtPassing yes

    X11Forwarding no
    X11DisplayOffset 10
    PrintMotd no
    #PrintLastLog no
    KeepAlive yes
    #UseLogin no

    #MaxStartups 10:30:60
    #Banner /etc/issue.net
    #ReverseMappingCheck yes

    Subsystem sftp /usr/lib/sftp-server

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Andreas Janssen: "Re: How to match kernel_headers and kernel versions?"

    Relevant Pages

    • Re: Hilfe bei OpenSSH for Windows
      ... # This is the sshd server system-wide configuration file. ... # HostKey for protocol version 1 ... # To disable tunneled clear text passwords, ... # Kerberos options ...
      (microsoft.public.de.security.netzwerk.sicherheit)
    • SSH Close to working, but need help!
      ... connecting to host with "public authentication failed for user xxx" ... Protocol 2,1 ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (comp.security.ssh)
    • problem on sshd setup: public key support
      ... Now I have some problem to setup public key authentication: ... Server refused our key ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing only works with the AFS ...
      (comp.os.linux.misc)
    • ssh help
      ... However I now cannot get host based authentication to work as it did ... # HostKey for protocol version 1 ... HostKey /etc/ssh_host_key ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (Focus-SUN)
    • RE: ssh configuration problem
      ... I would also recommend setting Protocol to 1,2 instead of 2, this will let ... after this when i tried to restart the sshd service it fails ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (SSH)