Gentoo Archives: gentoo-hardened

From: Dan Reidy <dubkat@×××××.com>
To: gentoo-hardened@l.g.o
Cc: "Reidy, Daniel" <dubkat@×××××.com>
Subject: [gentoo-hardened] SSH nolonger works after update
Date: Fri, 07 Mar 2008 19:07:10
Message-Id: 200803071406.16440.dubkat@gmail.com
1 Hello Ladies and Gentlemen,
2 Forgive me if this is an innapropriate topic for this list, but I figured
3 it's full of people with know-how, and also the most active of the lists
4 I'm subscribed to.
5
6 The Scenerio:
7 I have crappy bandwidth at home, so I use a headless, gentoo-hardened server
8 at a family members house who travels alot and not using their bandwidth.
9 After running an update yesterday, I can no longer login to the machine.
10 Log pasted below. Before my family member left for a trip, I had them reboot
11 the machine, but that didn't solve it... Nor could they login from the
12 local network. I am completely at a loss as to how to fix this. Hooking up
13 a monitor and keyboard is not an option.
14
15 Any ideas?
16
17 dubkat@synergy ~ $ ssh -vv HOST.SCRUBBED
18 OpenSSH_4.7p1, OpenSSL 0.9.8g 19 Oct 2007
19 debug1: Reading configuration data /home/dubkat/.ssh/config
20 debug1: Applying options for *
21 debug1: Reading configuration data /etc/ssh/ssh_config
22 debug2: ssh_connect: needpriv 0
23 debug1: Connecting to SCRUBBED [xx.xx.xx.xx] port 22.
24 debug1: Connection established.
25 debug1: identity file /home/dubkat/.ssh/identity type -1
26 debug1: identity file /home/dubkat/.ssh/id_rsa type 1
27 debug2: key_type_from_name: unknown key type '-----BEGIN'
28 debug2: key_type_from_name: unknown key type '-----END'
29 debug1: identity file /home/dubkat/.ssh/id_dsa type 2
30 debug1: Remote protocol version 2.0, remote software version OpenSSH_4.7
31 debug1: match: OpenSSH_4.7 pat OpenSSH*
32 debug1: Enabling compatibility mode for protocol 2.0
33 debug1: Local version string SSH-2.0-OpenSSH_4.7
34 debug2: fd 3 setting O_NONBLOCK
35 debug1: SSH2_MSG_KEXINIT sent
36 debug1: SSH2_MSG_KEXINIT received
37 debug2: kex_parse_kexinit:
38 diffie-hellman-group-exchange-sha256,diffie-hellman-g
39 roup-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
40 debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
41 debug2: kex_parse_kexinit:
42 aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,
43 aes192-cbc,aes256-cbc
44 debug2: kex_parse_kexinit:
45 aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,
46 aes192-cbc,aes256-cbc
47 debug2: kex_parse_kexinit:
48 hmac-md5,hmac-sha1,umac-64@×××××××.com,hmac-ripemd160
49 ,hmac-ripemd160@×××××××.com,hmac-sha1-96,hmac-md5-96
50 debug2: kex_parse_kexinit:
51 hmac-md5,hmac-sha1,umac-64@×××××××.com,hmac-ripemd160
52 ,hmac-ripemd160@×××××××.com,hmac-sha1-96,hmac-md5-96
53 debug2: kex_parse_kexinit: none,zlib@×××××××.com,zlib
54 debug2: kex_parse_kexinit: none,zlib@×××××××.com,zlib
55 debug2: kex_parse_kexinit:
56 debug2: kex_parse_kexinit:
57 debug2: kex_parse_kexinit: first_kex_follows 0
58 debug2: kex_parse_kexinit: reserved 0
59 debug2: kex_parse_kexinit:
60 diffie-hellman-group-exchange-sha256,diffie-hellman-g
61 roup-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
62 debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
63 debug2: kex_parse_kexinit:
64 aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour1
65 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@×××××××××××.se,aes128-c
66 tr,aes192-ctr,aes256-ctr
67 debug2: kex_parse_kexinit:
68 aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour1
69 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@×××××××××××.se,aes128-c
70 tr,aes192-ctr,aes256-ctr
71 debug2: kex_parse_kexinit:
72 hmac-md5,hmac-sha1,umac-64@×××××××.com,hmac-ripemd160
73 ,hmac-ripemd160@×××××××.com,hmac-sha1-96,hmac-md5-96
74 debug2: kex_parse_kexinit:
75 hmac-md5,hmac-sha1,umac-64@×××××××.com,hmac-ripemd160
76 ,hmac-ripemd160@×××××××.com,hmac-sha1-96,hmac-md5-96
77 debug2: kex_parse_kexinit: none,zlib@×××××××.com
78 debug2: kex_parse_kexinit: none,zlib@×××××××.com
79 debug2: kex_parse_kexinit:
80 debug2: kex_parse_kexinit:
81 debug2: kex_parse_kexinit: first_kex_follows 0
82 debug2: kex_parse_kexinit: reserved 0
83 debug2: mac_setup: found hmac-md5
84 debug1: kex: server->client aes128-cbc hmac-md5 none
85 debug2: mac_setup: found hmac-md5
86 debug1: kex: client->server aes128-cbc hmac-md5 none
87 debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
88 debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
89 debug2: dh_gen_key: priv key bits set: 118/256
90 debug2: bits set: 521/1024
91 debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
92 debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
93 debug1: Host 'HOSTNAME.SCRUBBED' is known and matches the RSA host key.
94 debug1: Found key in /home/dubkat/.ssh/known_hosts:19
95 debug2: bits set: 523/1024
96 debug1: ssh_rsa_verify: signature correct
97 debug2: kex_derive_keys
98 debug2: set_newkeys: mode 1
99 debug1: SSH2_MSG_NEWKEYS sent
100 debug1: expecting SSH2_MSG_NEWKEYS
101 debug2: set_newkeys: mode 0
102 debug1: SSH2_MSG_NEWKEYS received
103 debug1: SSH2_MSG_SERVICE_REQUEST sent
104 debug2: service_accept: ssh-userauth
105 debug1: SSH2_MSG_SERVICE_ACCEPT received
106 debug2: key: /home/dubkat/.ssh/identity ((nil))
107 debug2: key: /home/dubkat/.ssh/id_rsa (0x6656a0)
108 debug2: key: /home/dubkat/.ssh/id_dsa (0x669db0)
109
110
111 *** WARNING *** *** WARNING *** *** WARNING ***
112
113 THIS IS A PRIVATE MACHINE.
114 NO UNAUTHORIZED ACCESS PERMITTED.
115 BRUTE FORCE ATTEMPTS WILL BE REPORTED TO YOUR ISP
116
117 *** WARNING *** *** WARNING *** *** WARNING ***
118
119
120 debug1: Authentications that can continue: publickey,keyboard-interactive
121 debug1: Next authentication method: publickey
122 debug1: Trying private key: /home/dubkat/.ssh/identity
123 debug1: Offering public key: /home/dubkat/.ssh/id_rsa
124 debug2: we sent a publickey packet, wait for reply
125 debug1: Authentications that can continue: publickey,keyboard-interactive
126 debug1: Offering public key: /home/dubkat/.ssh/id_dsa
127 debug2: we sent a publickey packet, wait for reply
128 debug1: Authentications that can continue: publickey,keyboard-interactive
129 debug2: we did not send a packet, disable method
130 debug1: Next authentication method: keyboard-interactive
131 debug2: userauth_kbdint
132 debug2: we sent a keyboard-interactive packet, wait for reply
133 debug1: Authentications that can continue: publickey,keyboard-interactive
134 debug2: we did not send a packet, disable method
135 debug1: No more authentication methods to try.
136 Permission denied (publickey,keyboard-interactive).
137
138
139
140 --
141 -==========================================-
142
143 Avoid the Gates of Hell. Use Linux.
144 The choice of a GNU Generation.
145
146 Daniel J Reidy RipeID: DJR9-RIPE
147 dubkat@×××××.com GPG Key: 0x36833401
148 http://sigterm.us/
149
150 -==========================================-

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] SSH nolonger works after update brant williams <brant@×××××.net>