Re: sshd + tcp_wrappers: nefunguje PARANOID ?!
To |
Debian CZ/SK project discussion list <czdebian-l zavinac debian bod cz> |
From |
Václav Ovsík <vaclav bod ovsik zavinac i bod cz> |
Date |
Fri, 28 Jan 2005 12:25:10 +0100 |
Mail-followup-to |
Debian CZ/SK project discussion list <czdebian-l zavinac debian bod cz> |
User-agent |
Mutt/1.5.6i |
On Thu, Jan 27, 2005 at 10:03:47PM +0100, Karel Petru wrote:
> Pro sshd 3.4 byl parametr v configu VerifyReversMapping. To ale asi
> nebude tento problem.
Dobra myslenka. Priznam se, ze jsem ani nekoukal do sshd_config, protoze
jsem asi tise predpokladal, ze jakmile neprojde neco pres tcp_wrappers,
tak uz by to nemelo jit dal ani pres nejake dalsi kontroly.
Tak ted jsem nahledl do sshd_config.
Nasel tam zakomentovane ReverseMappingCheck, takze napred jsem dal
ReverseMappingCheck yes
nepomohlo. Koukal jsem do manu od sshd_config a tam pisou pouze
o VerifyReverseMapping. Tak jsem prifal i
VerifyReverseMapping yes
a taky nepomohlo.
Takze ted uz mam PARANOID pro ALL v hosts.deny a ty dve directivy vyse
a vono to sakrys porad funguje:
na svem stroji jsem si pridal
bobek:~# ifconfig eth0:1 192.168.20.180
a delam
zito zavinac bobek zito $ ssh -b 192.168.20.180 -p 2999 fog
na fog jsem dal:
fog:~# sshd -D -d -p 2999
debug1: sshd version OpenSSH_3.4p1 Debian 1:3.4p1-1.woody.3
debug1: private host key: #0 type 0 RSA1
debug1: read PEM private key done: type RSA
debug1: private host key: #1 type 1 RSA
debug1: read PEM private key done: type DSA
debug1: private host key: #2 type 2 DSA
debug1: Bind to port 2999 on 0.0.0.0.
Server listening on 0.0.0.0 port 2999.
debug1: Server will not fork when running in debugging mode.
Connection from 192.168.20.180 port 34717
debug1: Client protocol version 2.0; client software version OpenSSH_3.4p1
Debian 1:3.4p1-1.woody.3
debug1: match: OpenSSH_3.4p1 Debian 1:3.4p1-1.woody.3 pat OpenSSH*
Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1.woody.3
debug1: list_hostkey_types: ssh-rsa,ssh-dss
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: client->server aes128-cbc hmac-md5 none
debug1: kex: server->client aes128-cbc hmac-md5 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST received
debug1: SSH2_MSG_KEX_DH_GEX_GROUP sent
debug1: dh_gen_key: priv key bits set: 134/256
debug1: bits set: 1602/3191
debug1: expecting SSH2_MSG_KEX_DH_GEX_INIT
debug1: bits set: 1546/3191
debug1: SSH2_MSG_KEX_DH_GEX_REPLY sent
debug1: kex_derive_keys
debug1: newkeys: mode 1
debug1: SSH2_MSG_NEWKEYS sent
debug1: waiting for SSH2_MSG_NEWKEYS
debug1: newkeys: mode 0
debug1: SSH2_MSG_NEWKEYS received
debug1: KEX done
debug1: userauth-request for user zito service ssh-connection method none
debug1: attempt 0 failures 0
debug1: Starting up PAM with username "zito"
Could not reverse map address 192.168.20.180.
debug1: PAM setting rhost to "192.168.20.180"
Failed none for zito from 192.168.20.180 port 34717 ssh2
Failed none for zito from 192.168.20.180 port 34717 ssh2
debug1: userauth-request for user zito service ssh-connection method publickey
debug1: attempt 1 failures 1
debug1: test whether pkalg/pkblob are acceptable
debug1: temporarily_use_uid: 1000/1000 (e=0)
debug1: trying public key file /home/zito/.ssh/authorized_keys
debug1: matching key found: file /home/zito/.ssh/authorized_keys, line 2
Found matching RSA key: 8f:23:fc:1f:01:49:a7:f8:93:f5:c0:bb:d2:fa:81:36
debug1: restore_uid
Postponed publickey for zito from 192.168.20.180 port 34717 ssh2
debug1: userauth-request for user zito service ssh-connection method publickey
debug1: attempt 2 failures 1
debug1: temporarily_use_uid: 1000/1000 (e=0)
debug1: trying public key file /home/zito/.ssh/authorized_keys
debug1: matching key found: file /home/zito/.ssh/authorized_keys, line 2
Found matching RSA key: 8f:23:fc:1f:01:49:a7:f8:93:f5:c0:bb:d2:fa:81:36
debug1: restore_uid
debug1: ssh_rsa_verify: signature correct
Accepted publickey for zito from 192.168.20.180 port 34717 ssh2
debug1: monitor_child_preauth: zito has been authenticated by privileged process
Accepted publickey for zito from 192.168.20.180 port 34717 ssh2
debug1: PAM establishing creds
debug1: newkeys: mode 0
debug1: newkeys: mode 1
debug1: Entering interactive session for SSH2.
debug1: fd 7 setting O_NONBLOCK
debug1: fd 8 setting O_NONBLOCK
debug1: server_init_dispatch_20
debug1: server_input_channel_open: ctype session rchan 0 win 65536 max 16384
debug1: input_session_request
debug1: channel 0: new [server-session]
debug1: session_new: init
debug1: session_new: session 0
debug1: session_open: channel 0
debug1: session_open: session 0: link with channel 0
debug1: server_input_channel_open: confirm session
debug1: server_input_channel_req: channel 0 request pty-req reply 0
debug1: session_by_channel: session 0 channel 0
debug1: session_input_channel_req: session 0 req pty-req
debug1: Allocating pty.
debug1: session_new: init
debug1: session_new: session 0
debug1: session_pty_req: session 0 alloc /dev/pts/3
debug1: server_input_channel_req: channel 0 request shell reply 0
debug1: session_by_channel: session 0 channel 0
debug1: session_input_channel_req: session 0 req shell
debug1: PAM setting tty to "/dev/pts/3"
debug1: PAM establishing creds
debug1: fd 4 setting TCP_NODELAY
debug1: Setting controlling tty using TIOCSCTTY.
debug1: channel 0: rfd 10 isatty
debug1: fd 10 setting O_NONBLOCK
Konstatuje, ze se mu nepovedl reverse mapping, ale jede dal..
Tak ja nevim. Asi jsem neco blbe pochopil...
--
Zito
Partial thread listing: