16 May 2013 17:16
Kerberos SSH
Martin Häggström <hejpadej <at> spray.se>
2013-05-16 15:16:25 GMT
2013-05-16 15:16:25 GMT
Hi again!
Some of you have followed me through my attempts to use kerberized services. I have managed to ssh from both Ubuntu and FreeBSD to an Ubuntuserver. Right now I am trying to ssh from Ubuntu and FreeBSD to a FreeBSD ssh server. I can get the ticket from the kdc on Ubuntu but have problem reaching the FreeBSD server. I started the ssh server on FreeBSD like this, /usr/sbin/sshd -ddd -p 2020. It looks like it doesn't receive any credentials from the clients as you can see in the debug.
Ubuntu ubuntuclient.hemma.local
ssh -vvv -p 2020 martin <at> testserver.hemma.local
debug3: preferred gssapi-with-mic
debug3: authmethod_lookup gssapi-with-mic
debug3: remaining preferred:
debug3: authmethod_is_enabled gssapi-with-mic
debug1: Next authentication method: gssapi-with-mic
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we did not send a packet, disable method
debug1: No more authentication methods to try.
Permission denied (publickey,gssapi-with-mic,keyboard-interactive).
FreeBSD testserver.hemma.local
debug3: Trying to reverse map address 192.168.1.216.
debug1: userauth-request for user martin service ssh-connection method none
debug1: attempt 0 failures 0
debug3: mm_getpwnamallow entering
debug3: mm_request_send entering: type 6
debug3: mm_getpwnamallow: waiting for MONITOR_ANS_PWNAM
debug3: mm_request_receive_expect entering: type 7
debug3: mm_request_receive entering
debug3: monitor_read: checking request 6
debug3: mm_answer_pwnamallow
debug3: Trying to reverse map address 192.168.1.216.
debug2: parse_server_config: config reprocess config len 250
debug3: mm_answer_pwnamallow: sending MONITOR_ANS_PWNAM: 1
debug3: mm_request_send entering: type 7
debug2: monitor_read: 6 used once, disabling now
debug3: mm_request_receive entering
debug2: input_userauth_request: setting up authctxt for martin
debug3: mm_start_pam entering
debug3: mm_request_send entering: type 45
debug3: monitor_read: checking request 45
debug3: mm_inform_authserv entering
debug1: PAM: initializing for "martin"
debug3: mm_request_send entering: type 3
debug2: input_userauth_request: try method none
debug1: PAM: setting PAM_RHOST to "ubuntuclient.hemma.local"
debug2: monitor_read: 45 used once, disabling now
debug3: mm_request_receive entering
debug3: monitor_read: checking request 3
debug3: mm_answer_authserv: service=ssh-connection, style=
debug2: monitor_read: 3 used once, disabling now
debug3: mm_request_receive entering
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 1 failures 0
debug2: input_userauth_request: try method gssapi-with-mic
debug3: mm_request_send entering: type 37
debug3: mm_request_receive_expect entering: type 38
debug3: mm_request_receive entering
debug3: monitor_read: checking request 37
debug3: mm_request_send entering: type 38
debug3: mm_request_receive entering
Postponed gssapi-with-mic for martin from 192.168.1.216 port 54878 ssh2
debug3: mm_request_send entering: type 39
debug3: mm_request_receive_expect entering: type 40
debug3: mm_request_receive entering
debug3: monitor_read: checking request 39
debug1: Got no client credentials
debug3: mm_request_send entering: type 40
debug3: mm_request_receive entering
debug3: mm_request_send entering: type 43
debug3: mm_request_receive_expect entering: type 44
debug3: mm_request_receive entering
debug3: monitor_read: checking request 43
debug3: mm_request_send entering: type 44
debug3: mm_request_receive entering
debug3: mm_request_send entering: type 41
debug3: mm_request_receive_expect entering: type 42
debug3: mm_request_receive entering
debug3: monitor_read: checking request 41
debug3: mm_answer_gss_userok: sending result 0
debug3: mm_request_send entering: type 42
Failed gssapi-with-mic for martin from 192.168.1.216 port 54878 ssh2
debug3: mm_ssh_gssapi_userok: user not authenticated
debug3: mm_request_receive entering
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 2 failures 1
debug2: input_userauth_request: try method gssapi-with-mic
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 3 failures 2
debug2: input_userauth_request: try method gssapi-with-mic
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 4 failures 3
debug2: input_userauth_request: try method gssapi-with-mic
Connection closed by 192.168.1.216
Cheers Martin
Some of you have followed me through my attempts to use kerberized services. I have managed to ssh from both Ubuntu and FreeBSD to an Ubuntuserver. Right now I am trying to ssh from Ubuntu and FreeBSD to a FreeBSD ssh server. I can get the ticket from the kdc on Ubuntu but have problem reaching the FreeBSD server. I started the ssh server on FreeBSD like this, /usr/sbin/sshd -ddd -p 2020. It looks like it doesn't receive any credentials from the clients as you can see in the debug.
Ubuntu ubuntuclient.hemma.local
ssh -vvv -p 2020 martin <at> testserver.hemma.local
debug3: preferred gssapi-with-mic
debug3: authmethod_lookup gssapi-with-mic
debug3: remaining preferred:
debug3: authmethod_is_enabled gssapi-with-mic
debug1: Next authentication method: gssapi-with-mic
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we sent a gssapi-with-mic packet, wait for reply
debug1: Authentications that can continue: publickey,gssapi-with-mic,keyboard-interactive
debug2: we did not send a packet, disable method
debug1: No more authentication methods to try.
Permission denied (publickey,gssapi-with-mic,keyboard-interactive).
FreeBSD testserver.hemma.local
debug3: Trying to reverse map address 192.168.1.216.
debug1: userauth-request for user martin service ssh-connection method none
debug1: attempt 0 failures 0
debug3: mm_getpwnamallow entering
debug3: mm_request_send entering: type 6
debug3: mm_getpwnamallow: waiting for MONITOR_ANS_PWNAM
debug3: mm_request_receive_expect entering: type 7
debug3: mm_request_receive entering
debug3: monitor_read: checking request 6
debug3: mm_answer_pwnamallow
debug3: Trying to reverse map address 192.168.1.216.
debug2: parse_server_config: config reprocess config len 250
debug3: mm_answer_pwnamallow: sending MONITOR_ANS_PWNAM: 1
debug3: mm_request_send entering: type 7
debug2: monitor_read: 6 used once, disabling now
debug3: mm_request_receive entering
debug2: input_userauth_request: setting up authctxt for martin
debug3: mm_start_pam entering
debug3: mm_request_send entering: type 45
debug3: monitor_read: checking request 45
debug3: mm_inform_authserv entering
debug1: PAM: initializing for "martin"
debug3: mm_request_send entering: type 3
debug2: input_userauth_request: try method none
debug1: PAM: setting PAM_RHOST to "ubuntuclient.hemma.local"
debug2: monitor_read: 45 used once, disabling now
debug3: mm_request_receive entering
debug3: monitor_read: checking request 3
debug3: mm_answer_authserv: service=ssh-connection, style=
debug2: monitor_read: 3 used once, disabling now
debug3: mm_request_receive entering
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 1 failures 0
debug2: input_userauth_request: try method gssapi-with-mic
debug3: mm_request_send entering: type 37
debug3: mm_request_receive_expect entering: type 38
debug3: mm_request_receive entering
debug3: monitor_read: checking request 37
debug3: mm_request_send entering: type 38
debug3: mm_request_receive entering
Postponed gssapi-with-mic for martin from 192.168.1.216 port 54878 ssh2
debug3: mm_request_send entering: type 39
debug3: mm_request_receive_expect entering: type 40
debug3: mm_request_receive entering
debug3: monitor_read: checking request 39
debug1: Got no client credentials
debug3: mm_request_send entering: type 40
debug3: mm_request_receive entering
debug3: mm_request_send entering: type 43
debug3: mm_request_receive_expect entering: type 44
debug3: mm_request_receive entering
debug3: monitor_read: checking request 43
debug3: mm_request_send entering: type 44
debug3: mm_request_receive entering
debug3: mm_request_send entering: type 41
debug3: mm_request_receive_expect entering: type 42
debug3: mm_request_receive entering
debug3: monitor_read: checking request 41
debug3: mm_answer_gss_userok: sending result 0
debug3: mm_request_send entering: type 42
Failed gssapi-with-mic for martin from 192.168.1.216 port 54878 ssh2
debug3: mm_ssh_gssapi_userok: user not authenticated
debug3: mm_request_receive entering
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 2 failures 1
debug2: input_userauth_request: try method gssapi-with-mic
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 3 failures 2
debug2: input_userauth_request: try method gssapi-with-mic
debug1: userauth-request for user martin service ssh-connection method gssapi-with-mic
debug1: attempt 4 failures 3
debug2: input_userauth_request: try method gssapi-with-mic
Connection closed by 192.168.1.216
Cheers Martin
_______________________________________________________________
Annons: Skaffa Spray Mail du också - Gratis, enkelt och säkert!
RSS Feed