Re: OpenSSH Assistance - New Admin



Joe Pfeiffer wrote:

Günther Schwarz <strap@xxxxxx> writes:

He or she won't get a warning. The connection will simply break like
the one the OP posted. He might check if he changed the keys in
/etc/ssh during the upgrade.

Yes, you get a warning about a possible man-in-the-middle attack
because the key changed.

Sorry, I messed that up. You're right. But as the connection is closed
after the warning the user has no chance to correct the error without
verifying the new key settings with the server admin. This is a nasty
situation in a environment where lots of people log in with ssh. Email
is not trustworthy and snail mail is expensive. Recording the MD5 sum
of the new public key on an answering machine might do the trick.

Günther
.



Relevant Pages

  • Re: OpenSSH Assistance - New Admin
    ... Joe Pfeiffer wrote: ... But as the connection is ... closed after the warning the user has no chance to correct the error ... This is configurable with the StrictHostKeyChecking setting (and ...
    (comp.os.linux.networking)
  • system fails to boot after /usr/lib/ld.so.1 file is overwritten
    ... Bus ErrorConnection to tru-sd-comhub closed. ... Connection closed by remote host ... WARNING: forceload of misc/md_trans failed ... WARNING - fatal error from fsck - error 137 ...
    (SunManagers)
  • Re: [Full-disclosure] Packet sniffing help needed
    ... > Comp1= Windows xp box, Connected via dial up to a free ISP ... accessed a standard POP3 or FTP server over an insecure connection (i.e. ... The attacker doesn't really have to do anything ... But if the user dismisses this warning without ...
    (Full-Disclosure)
  • Re: Merging from Access database on server
    ... What type of connection are you using? ... Are they seeing the SQL warning dialog? ... The database and merge documents are located on a server that ...
    (microsoft.public.word.mailmerge.fields)
  • The server you are connected to is using a security certificate th
    ... I am getting the above warning every time I open vista widowns mail. ... Change the POP server to pop.att.yahoo.com. ... connection. ...
    (microsoft.public.windows.vista.mail)