Fwd: openssh a kerberos4 authentication

dejfson dejfson na gmail.com
Úterý Prosinec 11 00:53:24 CET 2007


sem se nejak uklepl jeste jsem to nestacil dopsat.....

zkousel jsem jak openssh_4.3 tak nejnovejsi 4.7, vysledek je pokazde stejny.
pro SSH1 pouze password, pro SSH2 funguje GSSAPI ale autorizace neprobehne s
nejakou bizardni chybou. Hledal jsem jak jsou nastavene nase servery a nasel
jsem ze pouzivaji SSH1 a krb4.
pouzivam gentoo, mam USE = kerberos krb4
mam nainstalovany mit-krb5

---------------------- konfigurak ssh:
 Host *
   ForwardAgent no
   ForwardX11 yes
#   RhostsRSAAuthentication no
#   RSAAuthentication yes
   PasswordAuthentication yes
   HostbasedAuthentication no
   GSSAPIAuthentication yes
#   BatchMode no
#   CheckHostIP yes
#   AddressFamily any
#   ConnectTimeout 0
#   StrictHostKeyChecking ask
#   IdentityFile ~/.ssh/identity
#   IdentityFile ~/.ssh/id_rsa
#   IdentityFile ~/.ssh/id_dsa
#   Port 22
   Protocol 1,2
#   Cipher 3des
#   Ciphers
aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc
#   EscapeChar ~
   Tunnel yes
#   TunnelDevice any:any
#   PermitLocalCommand no
-----------------------------------------------------


a v logu dostanu pouze tohle:
fooker na sundra:~$ ssh -v -v -v lxplus.cern.ch
OpenSSH_4.3p2, OpenSSL 0.9.8g 19 Oct 2007
debug1: Reading configuration data /etc/ssh/ssh_config
debug2: ssh_connect: needpriv 0
debug1: Connecting to lxplus.cern.ch [137.138.5.232] port 22.
debug1: Connection established.
debug1: identity file /home/belohrad/.ssh/identity type -1
debug1: identity file /home/belohrad/.ssh/id_rsa type -1
debug1: identity file /home/belohrad/.ssh/id_dsa type -1
debug1: Remote protocol version 1.99, remote software version OpenSSH_4.3p2-
4.cern-hpn-CERN-4.3p2-4.cern
debug1: match: OpenSSH_4.3p2-4.cern-hpn-CERN-4.3p2-4.cern pat OpenSSH*
debug1: Local version string SSH-1.5-OpenSSH_4.3p2
debug2: fd 3 setting O_NONBLOCK
debug1: Waiting for server public key.
debug1: Received server public key (768 bits) and host key (1024 bits).
debug3: check_host_in_hostfile: filename /home/belohrad/.ssh/known_hosts
debug3: check_host_in_hostfile: match line 14
debug3: check_host_in_hostfile: filename /home/belohrad/.ssh/known_hosts
debug3: check_host_in_hostfile: match line 18
debug1: Host 'lxplus.cern.ch' is known and matches the RSA1 host key.
debug1: Found key in /home/belohrad/.ssh/known_hosts:14
debug1: Encryption type: 3des
debug1: Sent encrypted session key.
debug2: cipher_init: set keylen (16 -> 32)
debug2: cipher_init: set keylen (16 -> 32)
debug1: Installing crc compensation attack detector.
debug1: Received encrypted confirmation.
Permission denied.

-----------------------------------------------------

kdyz to provedu z jednoho z internich severu,autentizace probehne takto:

[lxplus241] /etc > ssh -v -v -v pslinux1
OpenSSH_4.3p2-4.cern-hpn, OpenSSL 0.9.7a Feb 19 2003
ssh(10953) debug1: Reading configuration data /etc/ssh/ssh_config
ssh(10953) debug1: Applying options for *
ssh(10953) debug2: ssh_connect: needpriv 0
ssh(10953) debug1: Connecting to pslinux1 [137.138.167.9] port 22.
ssh(10953) debug1: Connection established.
ssh(10953) debug1: identity file /afs/cern.ch/user/b/belohrad/.ssh/identity
type -1
ssh(10953) debug1: identity file /afs/cern.ch/user/b/belohrad/.ssh/id_rsa
type -1
ssh(10953) debug1: identity file /afs/cern.ch/user/b/belohrad/.ssh/id_dsa
type -1
ssh(10953) debug1: Remote protocol version 1.99, remote software version
OpenSSH_4.3p2-4.cern-hpn-CERN-4.3p2-4.cern
ssh(10953) debug1: match: OpenSSH_4.3p2-4.cern-hpn-CERN-4.3p2-4.cern pat
OpenSSH*
ssh(10953) debug1: Local version string SSH-1.5-OpenSSH_4.3p2-4.cern-hpn
ssh(10953) debug2: fd 3 setting O_NONBLOCK
ssh(10953) debug1: Waiting for server public key.
ssh(10953) debug1: Received server public key (768 bits) and host key (2048
bits).
ssh(10953) debug3: check_host_in_hostfile: filename
/afs/cern.ch/user/b/belohrad/.ssh/known_hosts
ssh(10953) debug3: check_host_in_hostfile: match line 3
ssh(10953) debug3: check_host_in_hostfile: filename
/afs/cern.ch/user/b/belohrad/.ssh/known_hosts
ssh(10953) debug3: check_host_in_hostfile: match line 4
ssh(10953) debug1: Host 'pslinux1' is known and matches the RSA1 host key.
ssh(10953) debug1: Found key in
/afs/cern.ch/user/b/belohrad/.ssh/known_hosts:3
ssh(10953) debug1: Encryption type: 3des
ssh(10953) debug1: Sent encrypted session key.
ssh(10953) debug2: cipher_init: set keylen (16 -> 32)
ssh(10953) debug2: cipher_init: set keylen (16 -> 32)
ssh(10953) debug1: Installing crc compensation attack detector.
ssh(10953) debug1: Received encrypted confirmation.
ssh(10953) debug1: Trying Kerberos v5 authentication.
ssh(10953) debug3: Trying to reverse map address 137.138.167.9.
ssh(10953) debug1: Kerberos v5 authentication failed.
ssh(10953) debug1: Trying Kerberos v4 authentication.
ssh(10953) debug1: Kerberos v4 authentication accepted.
ssh(10953) debug1: Kerberos v4 challenge successful.
ssh(10953) debug1: Kerberos v5 TGT forwarding failed.
ssh(10953) debug1: Kerberos v4 TGT forwarded (belohrad na CERN.CH).
ssh(10953) debug1: AFS token for cell cern.ch forwarded.
ssh(10953) debug1: Requesting pty.
ssh(10953) debug3: tty_make_modes: ospeed 38400
ssh(10953) debug3: tty_make_modes: ispeed 38400
ssh(10953) debug3: tty_make_modes: 1 3
ssh(10953) debug3: tty_make_modes: 2 28
ssh(10953) debug3: tty_make_modes: 3 8
ssh(10953) debug3: tty_make_modes: 4 21
ssh(10953) debug3: tty_make_modes: 5 4
ssh(10953) debug3: tty_make_modes: 6 0
ssh(10953) debug3: tty_make_modes: 7 0
ssh(10953) debug3: tty_make_modes: 8 17
ssh(10953) debug3: tty_make_modes: 9 19
ssh(10953) debug3: tty_make_modes: 10 26
ssh(10953) debug3: tty_make_modes: 12 18
ssh(10953) debug3: tty_make_modes: 13 23
ssh(10953) debug3: tty_make_modes: 14 22
ssh(10953) debug3: tty_make_modes: 18 15
ssh(10953) debug3: tty_make_modes: 30 0
ssh(10953) debug3: tty_make_modes: 31 0
ssh(10953) debug3: tty_make_modes: 32 0
ssh(10953) debug3: tty_make_modes: 33 0
ssh(10953) debug3: tty_make_modes: 34 0
ssh(10953) debug3: tty_make_modes: 35 0
ssh(10953) debug3: tty_make_modes: 36 1
ssh(10953) debug3: tty_make_modes: 37 0
ssh(10953) debug3: tty_make_modes: 38 0
ssh(10953) debug3: tty_make_modes: 39 0
ssh(10953) debug3: tty_make_modes: 40 0
ssh(10953) debug3: tty_make_modes: 41 0
ssh(10953) debug3: tty_make_modes: 50 1
ssh(10953) debug3: tty_make_modes: 51 1
ssh(10953) debug3: tty_make_modes: 52 0
ssh(10953) debug3: tty_make_modes: 53 1
ssh(10953) debug3: tty_make_modes: 54 1
ssh(10953) debug3: tty_make_modes: 55 1
ssh(10953) debug3: tty_make_modes: 56 0
ssh(10953) debug3: tty_make_modes: 57 0
ssh(10953) debug3: tty_make_modes: 58 0
ssh(10953) debug3: tty_make_modes: 59 1
ssh(10953) debug3: tty_make_modes: 60 1
ssh(10953) debug3: tty_make_modes: 61 1
ssh(10953) debug3: tty_make_modes: 62 0
ssh(10953) debug3: tty_make_modes: 70 1
ssh(10953) debug3: tty_make_modes: 71 0
ssh(10953) debug3: tty_make_modes: 72 1
ssh(10953) debug3: tty_make_modes: 73 0
ssh(10953) debug3: tty_make_modes: 74 0
ssh(10953) debug3: tty_make_modes: 75 0
ssh(10953) debug3: tty_make_modes: 90 1
ssh(10953) debug3: tty_make_modes: 91 1
ssh(10953) debug3: tty_make_modes: 92 0
ssh(10953) debug3: tty_make_modes: 93 0
ssh(10953) debug2: x11_get_proto: /usr/bin/X11/xauth  list
lxplus241.cern.ch:37.0 2>/dev/null
ssh(10953) debug1: Requesting X11 forwarding with authentication spoofing.
ssh(10953) debug2: fd 3 setting TCP_NODELAY
ssh(10953) debug1: Requesting shell.
ssh(10953) debug1: Entering interactive session.
ssh(10953) debug2: fd 0 setting O_NONBLOCK
ssh(10953) debug1: fd 0 clearing O_NONBLOCK
Last login: Mon Dec 10 23:29:42 2007 from lxplus213.cern.ch
================================================================
CS-CCR-DEV1 - 0874 R-0012 RA5616 - ab/co software development
================================================================
HP ProLiant DL380 G5 CZC65066J6
SMP 4x Intel(R) Xeon(R) CPU 5150 @ 2.66GHz 2666MHz (4096KB cache) 6912 MB
memory
Linux i686 2.6.9-55.0.12.EL.cernsmp (AFS: i386_linux26)
Scientific Linux CERN SLC release 4.6 (Beryllium)
================================================================



---------------
v mem pripade je videt ze openssh nechce pouzit krb5 a krb4. nevite nekdo
proc?

diky
db.



Další informace o konferenci Linux