Re: ssh client problem

From: Unruh (unruh-spam_at_physics.ubc.ca)
Date: 11/03/05


Date: 3 Nov 2005 19:48:42 GMT

vertigo <null@com.pl> writes:

>Hello

>I can't login from my machine to any other machine using ssh.
>(even to localhost). I can login from other machines to my machine.
>(i use password authentication for my sshd serwer)

a) you are sending the wong password.

b) the remote machine has disallowed root password login.
the second is more likely (the default in many systems).
 YOu cannot force someone else to use an
authentication method he does not want to use.

>My ssh_config:
># Host *
># ForwardAgent no
># ForwardX11 no
># RhostsAuthentication no
># RhostsRSAAuthentication no
># RSAAuthentication yes
># PasswordAuthentication yes
># HostbasedAuthentication no
># BatchMode no
># CheckHostIP yes
> StrictHostKeyChecking no
># IdentityFile ~/.ssh/identity
># IdentityFile ~/.ssh/id_rsa
># IdentityFile ~/.ssh/id_dsa
># Port 22
># Protocol 2,1
># Cipher 3des
># Ciphers
>aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-
>cbc
># EscapeChar ~

>Durring login attempt i am not asked about password, after a while
>permission denied is displayed:

>#ssh localhost -vvv
>OpenSSH_3.6p1, SSH protocols 1.5/2.0, OpenSSL 0x0090704f
>debug1: Reading configuration data /usr/local/etc/ssh_config
>debug1: Rhosts Authentication disabled, originating port will not be
>trusted.
>debug2: ssh_connect: needpriv 0
>debug1: Connecting to localhost [127.0.0.1] port 22.
>debug1: Connection established.
>debug1: identity file /root/.ssh/identity type -1
>debug1: identity file /root/.ssh/id_rsa type -1
>debug1: identity file /root/.ssh/id_dsa type -1
>debug1: Remote protocol version 1.99, remote software version
>OpenSSH_3.8.1p1
>debug1: match: OpenSSH_3.8.1p1 pat OpenSSH*
>debug1: Enabling compatibility mode for protocol 2.0
>debug1: Local version string SSH-2.0-OpenSSH_3.6p1
>debug1: SSH2_MSG_KEXINIT sent
>debug1: SSH2_MSG_KEXINIT received
>debug2: kex_parse_kexinit:
>diffie-hellman-group-exchange-sha1,diffie-hellman-group1-
>sha1
>debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
>debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-
>cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se
>debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-
>cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se
>debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-
>ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
>debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-
>ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
>debug2: kex_parse_kexinit: none,zlib
>debug2: kex_parse_kexinit: none,zlib
>debug2: kex_parse_kexinit:
>debug2: kex_parse_kexinit:
>debug2: kex_parse_kexinit: first_kex_follows 0
>debug2: kex_parse_kexinit: reserved 0
>debug2: kex_parse_kexinit:
>diffie-hellman-group-exchange-sha1,diffie-hellman-group1-
>sha1
>debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
>debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-
>cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-
>ctr,aes256-ctr
>debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-
>cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-
>ctr,aes256-ctr
>debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-
>ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
>debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-
>ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96
>debug2: kex_parse_kexinit: none,zlib
>debug2: kex_parse_kexinit: none,zlib
>debug2: kex_parse_kexinit:
>debug2: kex_parse_kexinit:
>debug2: kex_parse_kexinit: first_kex_follows 0
>debug2: kex_parse_kexinit: reserved 0
>debug2: mac_init: found hmac-md5
>debug1: kex: server->client aes128-cbc hmac-md5 none
>debug2: mac_init: found hmac-md5
>debug1: kex: client->server aes128-cbc hmac-md5 none
>debug1: SSH2_MSG_KEX_DH_GEX_REQUEST sent
>debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
>debug2: dh_gen_key: priv key bits set: 138/256
>debug2: bits set: 986/2048
>debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
>debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
>debug3: check_host_in_hostfile: filename /root/.ssh/known_hosts
>debug3: check_host_in_hostfile: match line 2
>debug1: Host 'localhost' is known and matches the RSA host key.
>debug1: Found key in /root/.ssh/known_hosts:2
>debug2: bits set: 1005/2048
>debug1: ssh_rsa_verify: signature correct
>debug2: kex_derive_keys
>debug2: set_newkeys: mode 1
>debug1: SSH2_MSG_NEWKEYS sent
>debug1: expecting SSH2_MSG_NEWKEYS
>debug2: set_newkeys: mode 0
>debug1: SSH2_MSG_NEWKEYS received
>debug1: SSH2_MSG_SERVICE_REQUEST sent
>debug2: service_accept: ssh-userauth
>debug1: SSH2_MSG_SERVICE_ACCEPT received
>debug1: Authentications that can continue:
>publickey,password,keyboard-interactive
>debug3: start over, passed a different list
>publickey,password,keyboard-interactive
>debug3: preferred publickey,keyboard-interactive,password
>debug3: authmethod_lookup publickey
>debug3: remaining preferred: keyboard-interactive,password
>debug3: authmethod_is_enabled publickey
>debug1: Next authentication method: publickey
>debug1: Trying private key: /root/.ssh/identity
>debug3: no such identity: /root/.ssh/identity
>debug1: Trying private key: /root/.ssh/id_rsa
>debug3: no such identity: /root/.ssh/id_rsa
>debug1: Trying private key: /root/.ssh/id_dsa
>debug3: no such identity: /root/.ssh/id_dsa
>debug2: we did not send a packet, disable method
>debug3: authmethod_lookup keyboard-interactive
>debug3: remaining preferred: password
>debug3: authmethod_is_enabled keyboard-interactive
>debug1: Next authentication method: keyboard-interactive
>debug2: userauth_kbdint
>debug2: we sent a keyboard-interactive packet, wait for reply
>debug1: Authentications that can continue:
>publickey,password,keyboard-interactive
>debug3: userauth_kbdint: disable: no info_req_seen
>debug2: we did not send a packet, disable method
>debug3: authmethod_lookup password
>debug3: remaining preferred:
>debug3: authmethod_is_enabled password
>debug1: Next authentication method: password
>debug3: packet_send2: adding 64 (len 49 padlen 15 extra_pad 64)
>debug2: we sent a password packet, wait for reply
>debug1: Authentications that can continue:
>publickey,password,keyboard-interactive
>Permission denied, please try again.
>debug3: packet_send2: adding 64 (len 49 padlen 15 extra_pad 64)
>debug2: we sent a password packet, wait for reply
>debug1: Authentications that can continue:
>publickey,password,keyboard-interactive
>Permission denied, please try again.
>debug3: packet_send2: adding 64 (len 49 padlen 15 extra_pad 64)
>debug2: we sent a password packet, wait for reply
>debug1: Authentications that can continue:
>publickey,password,keyboard-interactive
>debug2: we did not send a packet, disable method
>debug1: No more authentication methods to try.
>Permission denied (publickey,password,keyboard-interactive).
>debug1: Calling cleanup 0x8060f80(0x0)

>I tried to delete ~/.ssh/* but did not helped.
>Whats wrong ?

>Thanx
>Michal



Relevant Pages

  • Problem with some user autentification error on sshd
    ... debug1: Reading configuration data /etc/ssh/ssh_config ... debug2: kex_parse_kexinit: none,zlib ... debug3: check_host_in_hostfile: match line 3 ... debug1: Next authentication method: keyboard-interactive ...
    (SSH)
  • Re: Trouble with OpenSSH 3.4p1 - Cant connect with an RSA key pair
    ... >> I have a computer functioning as a server using RedHat 8.0 with OpenSSH ... I am experiencing a similar problem using passkey authentication with the ... < debug2: bits set: 1604/3191 ... < debug1: Server accepts key: pkalg ssh-rsa blen 149 ...
    (comp.security.ssh)
  • Public key authentication doesnt work
    ... the remote .ssh/authorized_keys but still the public key authentication ... debug1: Connection established. ... debug2: fd 3 setting O_NONBLOCK ...
    (comp.security.ssh)
  • Re: Trouble with OpenSSH 3.4p1 - Cant connect with an RSA key pair
    ... >> I am experiencing a similar problem using passkey authentication with the ... debug1: Reading configuration data /etc/ssh/ssh_config ... debug3: key_read: missing keytype ... debug2: kex_parse_kexinit: none,zlib ...
    (comp.security.ssh)
  • Re: interoperability question
    ... >debug2: we sent a password packet, ... >debug1: authentications that can continue: publickey,password ...
    (comp.security.ssh)