SSH version 2 "Server refused our key" error

From: Shahrizal Shaari (shahrizal_at_advi.co.jp)
Date: 08/19/03

  • Next message: Bennett R. Samowich: "SSH accepts protocol version 1.99"
    To: <secureshell@securityfocus.com>
    Date: Tue, 19 Aug 2003 15:58:31 +0900
    
    

    Hi everybody,

     I really need help on how to configure correctly in order to use SSH
    version 2.
    SSH version 1 works fine but when i try to use SSH version 2 i kept getting
    the
    "Server refused our key" error.
     I have been looking for the cause of the error but I could't find any.
    The key that i use is generated with "-t rsa -b 1024" command line option
    of the ssh-keygen command,and I copied the public key to the
    HOME/.ssh/authorized_keys2.

    Here is my server configuration file:

    # $OpenBSD: sshd_config,v 1.38 2001/04/15 21:41:29 deraadt Exp $

    # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin

    # This is the sshd server system-wide configuration file. See sshd(8)
    # for more information.

    Port 22
    Protocol 2,1
    #ListenAddress 0.0.0.0
    #ListenAddress ::
    HostKey /etc/ssh/ssh_host_key
    HostKey /etc/ssh/ssh_host_rsa_key
    HostKey /etc/ssh/ssh_host_dsa_key
    ServerKeyBits 768
    LoginGraceTime 600
    KeyRegenerationInterval 3600
    PermitRootLogin yes
    #
    # Don't read ~/.rhosts and ~/.shosts files
    IgnoreRhosts yes
    # Uncomment if you don't trust ~/.ssh/known_hosts for
    RhostsRSAAuthentication
    #IgnoreUserKnownHosts yes
    StrictModes yes
    X11Forwarding yes
    X11DisplayOffset 10
    PrintMotd yes
    #PrintLastLog no
    KeepAlive yes

    # Logging
    SyslogFacility AUTHPRIV
    LogLevel INFO
    #obsoletes QuietMode and FascistLogging

    RhostsAuthentication no
    #
    # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
    RhostsRSAAuthentication no
    # similar for protocol version 2
    HostbasedAuthentication no
    #
    RSAAuthentication yes

    # To disable tunneled clear text passwords, change to no here!
    PasswordAuthentication no
    PermitEmptyPasswords no

    # Uncomment to disable s/key passwords
    #ChallengeResponseAuthentication no

    # Uncomment to enable PAM keyboard-interactive authentication
    # Warning: enabling this may bypass the setting of 'PasswordAuthentication'
    #PAMAuthenticationViaKbdInt yes

    # To change Kerberos options
    #KerberosAuthentication no
    #KerberosOrLocalPasswd yes
    #AFSTokenPassing no
    #KerberosTicketCleanup no

    # Kerberos TGT Passing does only work with the AFS kaserver
    #KerberosTgtPassing yes

    #CheckMail yes
    #UseLogin no

    #MaxStartups 10:30:60
    #Banner /etc/issue.net
    #ReverseMappingCheck yes

    Subsystem sftp /usr/libexec/openssh/sftp-server


  • Next message: Bennett R. Samowich: "SSH accepts protocol version 1.99"

    Relevant Pages

    • Re: Attempting my first port forwarding through SSH
      ... you're surfing via the remote system with no software on the remote server other than sshd. ... I have changed some settings in the Firefox network set up to see if the problem solved, I changed socks5 for socks4 but nothing, and deleted the "No proxy for:localhost" to see if anything worked, but basically the browser still does nothing, I think my Firefox settings are correct. ... # To enable empty passwords, ... # Kerberos options ...
      (comp.security.ssh)
    • sshd and IPv4 forwarding no longer working
      ... I performed a recent upgrade and possibly openssh got upgraded as well. ... but not from another server. ... # To enable empty passwords, ... # Kerberos options ...
      (Ubuntu)
    • OpenSSH 3.6.1p2 Inoperability Issue
      ... I am running a Linux Debian server at home, ... sshd will not accept connections. ... passwords, even if it is correct, is just says access denied. ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (SSH)
    • OpenSSH Assistance - New Admin
      ... The first thing I was told was to upgrade our SSH server. ... # HostKeys for protocol version 2 ... # To enable empty passwords, ... # Kerberos TGT Passing does only work with the AFS kaserver ...
      (comp.os.linux.networking)
    • Re: ssh2 hostbased auth fails
      ... Actually the ssh client works fine,the problem is the scp and sftp client. ... Here is my configuration file. ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing does only work with the AFS kaserver ...
      (SSH)

  • Quantcast