Re: OpenSSH Assistance - New Admin



Maxwell wrote:

Sealg <sealgair03@xxxxxxxxx> writes:

The first thing I was told was to upgrade our SSH server. Since the
upgrade on friday no one can log into it. Not even as root on
localhost. Here is the -vv

If a user tries to connect to the upgraded service, they should get a
warning that the certificates have changed.

He or she won't get a warning. The connection will simply break like the
one the OP posted. He might check if he changed the keys in /etc/ssh
during the upgrade. If so, the entries for the server in the
ssh_known_hosts files on the clients have to be deleted prior to a new
login. Because of the security problem with OpenSSL on Debian [1] it
might be risky to restore the old keys from backup.

{1] http://lists.debian.org/debian-security-announce/2008/msg00152.html

Günther
.



Relevant Pages

  • Re: Critical Warining When Closing Gnome2
    ... table still has 1 element at quit time (keys above) ... hash table still has 1 element at quit time ... before I do a portupgrade. ... crafted upgrade script that is supposed to do the trick for you. ...
    (freebsd-questions)
  • Re: Snow Leopard WARNING!!
    ... have prepared a safety strategy, so if it all goes pear-shaped, they won't ... I have two Macs: I will upgrade one and test. ... I will put the DVD in the hole on MY computer :-) ... your warning did not push me to that - my plan already. ...
    (microsoft.public.mac.office.word)
  • OpenSSH 3.0.1p1 Solaris 2.5 - 8.0 Nightmares occuring
    ... I am having some really bad problems trying to upgrade our servers to ... having all kinds of issues with the keys. ... PS Am purchasing O'reilly's SSH book today, hopefully, it will ...
    (comp.security.ssh)
  • Re: SSH oddness with 8.0-STABLE
    ... over RSA for host and user authentication keys. ... upgrade, we've switched to the vendor's default of RSA over ... host keys even for previously known hosts. ...
    (freebsd-stable)
  • Re: Glass Cockpit, ages quicker ?
    ... > other "old style" gauges are more likely to fail without ... > warning and do not self-monitor. ... will demand that you upgrade components frequently. ... And, as you have pointed out, electronic hardware usually fails in the first ...
    (rec.aviation.student)