Hostbased auth problem

From: Chris Bryant (Chris.Bryant_at_DTAG.Com)
Date: 11/04/05

  • Next message: Flo Gleixner: "Re: passwordless login with heimdal (kerberos) on openssh 4.2p1"
    Date: Fri, 4 Nov 2005 08:51:58 -0600
    To: <secureshell@securityfocus.com>
    
    

    I have 3 hosts that I am trying to get hostbased authentication to work

    Host A is a Tru64 5.1B OS running OpenSSH_4.2p1
    Host B is a Redhat 9.0 OS running OpenSSH_3.5p1
    Host C is a AIX 5.3 OS running OpenSSH_3.8.1p1

    On all 3 servers in the sshd_config file HostbasedAuthentication is set
    to yes and Ignore Rhosts is set to no. On all 3 servers in the
    ssh_config file HostbasedAuthentication is set to yes and
    EnableSSHKeysign is set to yes. All 3 servers have the same account
    name and a .shosts file that has 600 permissions and is owned by the
    specific user. I can generate the key and I can use ssh-keyscan just
    fine.

    Host A can authenticate to Host B
    Host B can authenticate to Host A

    Host B can authenticate to Host C
    Host C can authenticate to Host B

    Host C can authenticate to Host A
    However, Host A cannot authenticate to Host C.

    Has anyone had this problem before of 2 different OS's running different
    versions of OpenSSH not being able to authenticated via hostbased
    authentication?

    Thanks,

    Chris


  • Next message: Flo Gleixner: "Re: passwordless login with heimdal (kerberos) on openssh 4.2p1"

    Relevant Pages

    • Re: etc/passwd file
      ... > The point is that any scheme such as this where the encrypted password is ... into a private dmz (say ssl via web, then an ssh through a secure java ... the host itself cannot be the means for authenticating itself... ... and then authenticate the user with some time of otp scheme (which gets ...
      (comp.security.unix)
    • Re: Unix client and secure DNS updates
      ... How to do this dynamic update from a Solaris host? ... Unix client to authenticate to AD using Kerberos, then perform a DNS ...
      (microsoft.public.windows.server.dns)
    • Re: how to pass authorization to another application
      ... The host application will authenticate the user, ... any forms being submitted to the other server. ... The most efficient solution is to push the encryption and validation down to ...
      (comp.lang.php)
    • Solaris login based on Windows Domain?
      ... way to "hook" Solaris logins to authenticate against ... Perhaps we DO want to create an account on every host for each user and ... replace /etc/shadow with the Windows Domain? ... * Solaris 9, latest media, latest patch cluster. ...
      (SunManagers)
    • LDAP - TLS/SSL - Testing
      ... I have managed to get Opneldap running in order to authenticate to my ... linux box which is an up to date 'testing'. ... apt-get install to install slapd etc and i think that i am right in ... host name in hosts of a1it.org, ldap is set as dc=a1it,dc=a1it.org. ...
      (Debian-User)