Re: incorrect "host key changed" for multi-sshd localhost

From: all mail refused (elvis@notatla.demon.co.uk)
Date: 11/16/02

  • Next message: Nico Kadel-Garcia: "Re: fork a background process und ssh"
    From: elvis@notatla.demon.co.uk (all mail refused)
    Date: Sat, 16 Nov 2002 10:04:28 +0000 (UTC)
    
    

    In article <ar511l$oa8$1@elm.cpu1808.adsl.bellglobal.com>, Ian! D. Allen wrote:
    >I have several machines at my College that set up reverse ssh tunnels
    >back to themselves via "ssh -R 123x:localhost:22 idallen.com". This means
    >idallen.com effectively has an sshd listening on several 123x ports.
    >
    >On idallen.com, the first time I connect to one of these localhost ports,
    >e.g. "ssh -p 1231 localhost", ssh puts an entry in .ssh/known_hosts for
    >"localhost"; but, of course, the key that is put there is the host key
    >for one of my *remote* machines, listening on port 1231.

    >Ideas?

    I'm not sure I aprove of your scheme - why not make arrangements your fw
    admin will agree to ?

    Anyway withan entire 127/8 to use I don't see why you need multiple keys
    to collide on the same IP.

    -- 
    decoy mail addresses: obtain username via 0x4f/tcp or 0x50/tcp
    random words follow - don't take too seriously!
     Hertz max, despite the message is not "free beer": you may find
     the business consequences of missing the goal of full deployment
     for the CISSP (Certified Information Systems Security Professional)
     exam and designation produced by National Trade Productions,
    


    Relevant Pages

    • Re: incorrect "host key changed" for multi-sshd localhost
      ... >I have several machines at my College that set up reverse ssh tunnels ... >idallen.com effectively has an sshd listening on several 123x ports. ... >for one of my *remote* machines, ...
      (comp.security.ssh)
    • Re: Mainpine IQ Express: PCI-Express multi-port fax board for the free Microsoft Fax Server
      ... The IQ Express does support it. ... except that testing from one set of ports back to another ... I like the results with Brother MFC machines. ... the Microsoft Fax Service that is included with Windows XP/2003 SBS/ ...
      (microsoft.public.windows.server.sbs)
    • Re: slow login problems at branch office
      ... Download PortQryUI and from the client side check to see if the ports are ... 389/TCP/UDP LDAP ... 53/TCP/UDP DNS ... SP4 machines and based in the main site. ...
      (microsoft.public.win2000.active_directory)
    • Re: Can access other PC by IP, but not by UNC name
      ... > Doublecheck if the built in firewall is disabled on both machines. ... The Windows firewall is disabled on both machines. ... is in the Trusted zone; the zone's security setting is set to ... medium (meaning all ports to this zone are open by default), ...
      (microsoft.public.windowsxp.network_web)
    • Re: slow login problems at branch office
      ... I tried all the ports you mentioned below and they all seemed to pass. ... 389/TCP/UDP LDAP ... 53/TCP/UDP DNS ... SP4 machines and based in the main site. ...
      (microsoft.public.win2000.active_directory)