2nd attempt: OSX/SSH Authentication Problem

From: James Hankins (jghankins_at_mac.com)
Date: 02/15/04

  • Next message: Miller Alan: "AW: UsersDeny except root@myserver"
    To: secureshell@securityfocus.com
    Date: Sun, 15 Feb 2004 08:04:47 -0500
    
    

            
    Greetings!

    I'm having a problem after compiling and installing OpenSSH_3.7.1p2 on
    my mac which is running 10.3.2.

    I installed to solve a periodic lockup problem that was occurring when
    using the included SSH. This appears to have been solved with the
    update but my ability to access the mac from remote using SSH is now
    broken. I keep getting permission denied after entering my password,
    no matter which user I use.

    I used the following options during compile

    /configure \
         --with-tcp-wrappers \
         --without-rsh \
         --prefix=/usr \
         --with-privsep-user=nobody \
         --mandir=/usr/share/man \
         --sysconfdir=/private/etc

    make
    sudo make install

    ------------------------------

    And here is the contents of my sshd_config

    Any ideas on how to fix or further debug would be greatly appreciated!

    jim-g5:/etc jim$ cat sshd_config
    # $OpenBSD: sshd_config,v 1.65 2003/08/28 12:54:34 markus Exp $

    # This is the sshd server system-wide configuration file. See
    # sshd_config(5) for more information.

    # This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin

    # The strategy used for options in the default sshd_config shipped with
    # OpenSSH is to specify options with their default value where
    # possible, but leave them commented. Uncommented options change a
    # default value.

    #Port 22
    #Protocol 2,1
    #ListenAddress 0.0.0.0
    #ListenAddress ::

    # HostKey for protocol version 1
    #HostKey /etc/ssh_host_key
    # HostKeys for protocol version 2
    #HostKey /etc/ssh_host_rsa_key
    #HostKey /etc/ssh_host_dsa_key

    # Lifetime and size of ephemeral version 1 server key
    #KeyRegenerationInterval 1h
    #ServerKeyBits 768

    # Logging
    #obsoletes QuietMode and FascistLogging
    #SyslogFacility AUTH
    #LogLevel INFO

    # Authentication:

    #LoginGraceTime 2m
    #PermitRootLogin yes
    #StrictModes yes

    #RSAAuthentication yes
    #PubkeyAuthentication yes
    #AuthorizedKeysFile .ssh/authorized_keys

    # For this to work you will also need host keys in /etc/ssh_known_hosts
    #RhostsRSAAuthentication no
    # similar for protocol version 2
    #HostbasedAuthentication no
    # Change to yes if you don't trust ~/.ssh/known_hosts for
    # RhostsRSAAuthentication and HostbasedAuthentication
    #IgnoreUserKnownHosts no
    # Don't read the user's ~/.rhosts and ~/.shosts files
    #IgnoreRhosts yes

    # To disable tunneled clear text passwords, change to no here!
    #PasswordAuthentication yes
    #PermitEmptyPasswords no

    # Change to no to disable s/key passwords
    #ChallengeResponseAuthentication yes

    # Kerberos options
    #KerberosAuthentication no
    #KerberosOrLocalPasswd yes
    #KerberosTicketCleanup yes

    # GSSAPI options
    #GSSAPIAuthentication no
    #GSSAPICleanupCreds yes

    # Set this to 'yes' to enable PAM authentication (via
    challenge-response)
    # and session processing. Depending on your PAM configuration, this may
    # bypass the setting of 'PasswordAuthentication'
    #UsePAM yes

    #AllowTcpForwarding yes
    #GatewayPorts no
    #X11Forwarding no
    #X11DisplayOffset 10
    #X11UseLocalhost yes
    #PrintMotd yes
    #PrintLastLog yes
    #KeepAlive yes
    #UseLogin no
    #UsePrivilegeSeparation yes
    #PermitUserEnvironment no
    #Compression yes
    #ClientAliveInterval 0
    #ClientAliveCountMax 3
    #UseDNS yes
    #PidFile /var/run/sshd.pid
    #MaxStartups 10

    # no default banner path
    #Banner /some/path

    # override default of no subsystems
    Subsystem sftp /usr/libexec/sftp-server


  • Next message: Miller Alan: "AW: UsersDeny except root@myserver"

    Relevant Pages

    • Re: Hilfe bei OpenSSH for Windows
      ... # This is the sshd server system-wide configuration file. ... # HostKey for protocol version 1 ... # To disable tunneled clear text passwords, ... # Kerberos options ...
      (microsoft.public.de.security.netzwerk.sicherheit)
    • PasswordAuthentication no doesent work
      ... Only passwords should not be allowed at all. ... I'm reading something like that at the book "SSH - the definitive ... RhostsRSAAuthentication no ... # Kerberos TGT Passing does only work with the AFS kaserver ...
      (comp.security.ssh)
    • Re: ssh2 hostbased auth fails
      ... Actually the ssh client works fine,the problem is the scp and sftp client. ... Here is my configuration file. ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing does only work with the AFS kaserver ...
      (SSH)
    • sftp connection closed
      ... ssh feature is work fine but sftp doesn't work normally. ... # HostKey for protocol version 1 ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (comp.unix.solaris)
    • sftp connection closed
      ... ssh feature is work fine but sftp doesn't work normally. ... # HostKey for protocol version 1 ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (comp.security.ssh)