Re: hostbased authentication

From: Richard E. Silverman (slade@shore.net)
Date: 12/21/01

  • Next message: strube@physik3.gwdg.XPAM.de: "Re: Strange OpenSSH error"

    From: slade@shore.net (Richard E. Silverman)
    Date: 21 Dec 2001 00:37:37 -0500
    
    

    > it looks liks it tries twice then gives up. (the telus.net address is the
    > real reverse of the client trying to access the server)

    It doesn't just try twice for the heck of it :) -- it tries once with each
    client host key.

    > Someone suggested its the dns doing it

    Well, it shouldn't be a DNS problem per se. You have
    HostbasedUsesNameFromPacketOnly set, which means that the server simply
    looks up a key using name in the client's authentication request. You
    just have to make sure you use the client's canonical hostname (according
    to itself) in the known_hosts list on the server.

    > and to change the host name in the known hosts, but using the rsa and
    > dsa keys in the known hosts, there doesnt seem to be a place to change
    > the hostname.

    Huh? A known-hosts entry looks like this:

      foo.bar.org,foo,10.1.1.2 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEAt...

    The hostname and addresses (if any) come first; just change them. If
    those are missing, that could be your problem.

    If this doesn't clear it up, use server-side debugging ("sshd -d") to
    troubleshoot further.

    -- 
      Richard Silverman
      slade@shore.net
    



    Relevant Pages

    • Re: VMware ESXi
      ... Virtual Server because my bios does not support virtualization. ... the vSpere client on my XP workstation. ... Now I want to create another VM on the same host this ... egg scenario if you have VMWare running with a DHCP assigned ...
      (microsoft.public.windows.server.sbs)
    • Re: VMware ESXi
      ... the vSpere client on my XP workstation. ... Now I want to create another VM on the same host this ... the VM server through the client and then click the DVD/CD Connect ... egg scenario if you have VMWare running with a DHCP assigned ...
      (microsoft.public.windows.server.sbs)
    • Re: VMware ESXi
      ... Now I want to create another VM on the same host this time ... Using the vSphere client on my desktop I can go ... the VM server through the client and then click the DVD/CD Connect ... egg scenario if you have VMWare running with a DHCP assigned ...
      (microsoft.public.windows.server.sbs)
    • Re: Banana Republic (was Re: OpenVMS Book Wins award)
      ... page but didn't look deeeply enough to see that the client was having to ... (for the same host). ... cross-site scripting constraint exercised by the browser (to prevent XSS ... but what is outside any HTTP protocol is "when a server gets told something" ...
      (comp.os.vms)
    • Re: cs-host, host header and destination
      ... I can understand why someone would want to cloak their ... > The CS-Host field is sent by the client. ... If the server is configured with host headers only, ...
      (microsoft.public.inetserver.iis)

  • Quantcast