Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Dealing with a second SSH key



Christian,

Before I go any further, please let me thank you for your time and patience.


> Check those requirements are met on the rsync-box:
> - modes of your homedir should be 755 or stricter
> - modes of your home/.ssh dir should be 700 or stricter
> - your homedir, home/.ssh and all its contents should be owned by 
> your user
> - modes of home/.ssh/authorized_keys (containing your pubkey) should
> be 600 or stricter

I have rechecked these (I always rely on Josh Glover's eminently clear
"Quick-n-Dirty Guide")
  
> ssh -vv -i /home/dir/.ssh/id_dsa_keyfile user@example.com
> could then be used to get a bit output from your client.

Well, we certainly *do* get some output. It's considerable, but since
I don't know what is important, I'll paste the whole thing below. One
thing I do notice is that there seems to be a request for RSA. Maybe I
should be generating an RSA key instead of DSA? Here it is:


    chuck@example.com:~$ ssh -vv -i /home/acmuller/.ssh/id_dsa_sat acmuller@example.com
    OpenSSH_5.1p1 Debian-3, OpenSSL 0.9.8g 19 Oct 2007
    Warning: Identity file /home/acmuller/.ssh/id_dsa_sat not accessible: No such file or directory.
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug1: Applying options for *
    debug2: ssh_connect: needpriv 0
    debug1: Connecting to 21dzk.l.u-tokyo.ac.jp [130.69.116.30] port 22.
    debug1: Connection established.
    debug1: identity file /home/chuck/.ssh/identity type -1
    debug1: identity file /home/chuck/.ssh/id_rsa type -1
    debug2: key_type_from_name: unknown key type '-----BEGIN'
    debug2: key_type_from_name: unknown key type '-----END'
    debug1: identity file /home/chuck/.ssh/id_dsa type 2
    debug1: Checking blacklist file /usr/share/ssh/blacklist.DSA-1024
    debug1: Checking blacklist file /etc/ssh/blacklist.DSA-1024
    debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3
    debug1: match: OpenSSH_4.3 pat OpenSSH*
    debug1: Enabling compatibility mode for protocol 2.0
    debug1: Local version string SSH-2.0-OpenSSH_5.1p1 Debian-3
    debug2: fd 3 setting O_NONBLOCK
    debug1: SSH2_MSG_KEXINIT sent
    debug1: SSH2_MSG_KEXINIT received
    debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
    debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
    debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@example.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@example.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@example.com,hmac-ripemd160,hmac-ripemd160@example.com,hmac-sha1-96,hmac-md5-96
    debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@example.com,hmac-ripemd160,hmac-ripemd160@example.com,hmac-sha1-96,hmac-md5-96
    debug2: kex_parse_kexinit: none,zlib@example.com,zlib
    debug2: kex_parse_kexinit: none,zlib@example.com,zlib
    debug2: kex_parse_kexinit: 
    debug2: kex_parse_kexinit: 
    debug2: kex_parse_kexinit: first_kex_follows 0 
    debug2: kex_parse_kexinit: reserved 0 
    debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
    debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
    debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@example.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@example.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@example.com,hmac-sha1-96,hmac-md5-96
    debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@example.com,hmac-sha1-96,hmac-md5-96
    debug2: kex_parse_kexinit: none,zlib@example.com
    debug2: kex_parse_kexinit: none,zlib@example.com
    debug2: kex_parse_kexinit: 
    debug2: kex_parse_kexinit: 
    debug2: kex_parse_kexinit: first_kex_follows 0 
    debug2: kex_parse_kexinit: reserved 0 
    debug2: mac_setup: found hmac-md5
    debug1: kex: server->client aes128-cbc hmac-md5 none
    debug2: mac_setup: found hmac-md5
    debug1: kex: client->server aes128-cbc hmac-md5 none
    debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
    debug2: dh_gen_key: priv key bits set: 130/256
    debug2: bits set: 513/1024
    debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
    debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
    debug1: Host '21dzk.l.u-tokyo.ac.jp' is known and matches the RSA host key.
    debug1: Found key in /home/chuck/.ssh/known_hosts:2
    debug2: bits set: 497/1024
    debug1: ssh_rsa_verify: signature correct
    debug2: kex_derive_keys
    debug2: set_newkeys: mode 1
    debug1: SSH2_MSG_NEWKEYS sent
    debug1: expecting SSH2_MSG_NEWKEYS
    debug2: set_newkeys: mode 0
    debug1: SSH2_MSG_NEWKEYS received
    debug1: SSH2_MSG_SERVICE_REQUEST sent
    debug2: service_accept: ssh-userauth
    debug1: SSH2_MSG_SERVICE_ACCEPT received
    debug2: key: /home/chuck/.ssh/identity ((nil))
    debug2: key: /home/chuck/.ssh/id_rsa ((nil))
    debug2: key: /home/chuck/.ssh/id_dsa (0x80060bb0)
    debug1: Authentications that can continue: publickey,gssapi-with-mic,password
    debug1: Next authentication method: gssapi-with-mic
    debug1: Unspecified GSS failure.  Minor code may provide more information
    No credentials cache found
    
    debug1: Unspecified GSS failure.  Minor code may provide more information
    No credentials cache found
    
    debug1: Unspecified GSS failure.  Minor code may provide more information
    
    
    debug2: we did not send a packet, disable method
    debug1: Next authentication method: publickey
    debug1: Trying private key: /home/chuck/.ssh/identity
    debug1: Trying private key: /home/chuck/.ssh/id_rsa
    debug1: Offering public key: /home/chuck/.ssh/id_dsa
    debug2: we sent a publickey packet, wait for reply
    debug1: Authentications that can continue: publickey,gssapi-with-mic,password
    debug2: we did not send a packet, disable method
    debug1: Next authentication method: password
    acmuller@example.com's password: {I typed in my password
    here}

    debug2: we sent a password packet, wait for reply
    debug1: Authentication succeeded (password).
    debug1: channel 0: new [client-session]
    debug2: channel 0: send open
    debug1: Requesting no-more-sessions@example.com
    debug1: Entering interactive session.
    debug2: callback start
    debug2: client_session2_setup: id 0
    debug2: channel 0: request pty-req confirm 1
    debug1: Sending environment.
    debug1: Sending env LC_ALL = en_US.UTF-8
    debug2: channel 0: request env confirm 0
    debug1: Sending env LANG = en_US.UTF-8
    debug2: channel 0: request env confirm 0
    debug2: channel 0: request shell confirm 1
    debug2: fd 3 setting TCP_NODELAY
    debug2: callback done
    debug2: channel 0: open confirm rwindow 0 rmax 32768
    debug2: channel_input_confirm: type 99 id 0
    debug2: PTY allocation request accepted on channel 0
    debug2: channel 0: rcvd adjust 131072
    debug2: channel_input_confirm: type 99 id 0
    debug2: shell request accepted on channel 0
    Last login: Fri Oct 10 21:58:28 2008 from s113.htokyofl11.vectant.ne.jp

Regards,

Chuck
 
-------------------

A. Charles Muller

Graduate School of Humanities and Sociology
Faculty of Letters
University of Tokyo
7-3-1 Hongo, Bunkyo-ku
Tokyo 113-0033, Japan 

Web Site: Resources for East Asian Language and Thought
http://www.acmuller.net

<acmuller[at]jj.em-net.ne.jp>   
Skype: charles.muller01


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links