<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH public key  authentication Issue in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200902#M324682</link>
    <description>Im not prompted for a password nor should I. publickey authentication is failing.</description>
    <pubDate>Mon, 19 May 2008 19:50:23 GMT</pubDate>
    <dc:creator>Jonathan Grymes</dc:creator>
    <dc:date>2008-05-19T19:50:23Z</dc:date>
    <item>
      <title>SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200900#M324680</link>
      <description>Has anyone experienced this issue trying to initiate an sftp connection using public key authentication. Need resolution.&lt;BR /&gt;&lt;BR /&gt;% sftp -vvv -F /h/data/global/EC/System/openssh/client/ssh_config xxxxxxxxx@xxx.xxx.xxx.xx&lt;BR /&gt;Connecting to xxx.xx.xx.xxx...&lt;BR /&gt;OpenSSH_4.4p1-hpn12v11, OpenSSL 0.9.7l 28 Sep 2006&lt;BR /&gt;HP-UX Secure Shell-A.04.40.011, HP-UX Secure Shell version&lt;BR /&gt;debug1: Reading configuration data /h/data/global/EC/System/openssh/client/ssh_config&lt;BR /&gt;debug3: cipher ok: aes256-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: aes192-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: aes128-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: aes256-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: aes192-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: aes128-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: cipher ok: 3des-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug3: ciphers ok: [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]&lt;BR /&gt;debug2: mac_init: found hmac-sha1&lt;BR /&gt;debug3: mac ok: hmac-sha1 [hmac-sha1,hmac-sha1-96]&lt;BR /&gt;debug2: mac_init: found hmac-sha1-96&lt;BR /&gt;debug3: mac ok: hmac-sha1-96 [hmac-sha1,hmac-sha1-96]&lt;BR /&gt;debug3: macs ok: [hmac-sha1,hmac-sha1-96]&lt;BR /&gt;debug3: RNG is ready, skipping seeding&lt;BR /&gt;debug2: ssh_connect: needpriv 0&lt;BR /&gt;debug1: Connecting to 162.58.35.198 [162.58.35.198] port 22.&lt;BR /&gt;debug1: Connection established.&lt;BR /&gt;debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_rsa.&lt;BR /&gt;debug2: key_type_from_name: unknown key type '-----BEGIN'&lt;BR /&gt;debug3: key_read: missing keytype&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug2: key_type_from_name: unknown key type '-----END'&lt;BR /&gt;debug3: key_read: missing keytype&lt;BR /&gt;debug1: identity file /h/data/global/EC/System/openssh/client/id_rsa type 1&lt;BR /&gt;debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_dsa.&lt;BR /&gt;debug2: key_type_from_name: unknown key type '-----BEGIN'&lt;BR /&gt;debug3: key_read: missing keytype&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug3: key_read: missing whitespace&lt;BR /&gt;debug2: key_type_from_name: unknown key type '-----END'&lt;BR /&gt;debug3: key_read: missing keytype&lt;BR /&gt;debug1: identity file /h/data/global/EC/System/openssh/client/id_dsa type 2&lt;BR /&gt;debug1: Remote protocol version 2.0, remote software version OpenSSH_3.6.1p2&lt;BR /&gt;debug1: match: OpenSSH_3.6.1p2 pat OpenSSH_3.*&lt;BR /&gt;debug1: Remote is NON-HPN aware&lt;BR /&gt;debug1: Enabling compatibility mode for protocol 2.0&lt;BR /&gt;debug1: Local version string SSH-2.0-OpenSSH_4.4p1-hpn12v11&lt;BR /&gt;debug2: fd 4 setting O_NONBLOCK&lt;BR /&gt;debug3: RNG is ready, skipping seeding&lt;BR /&gt;debug1: SSH2_MSG_KEXINIT sent&lt;BR /&gt;debug1: SSH2_MSG_KEXINIT received&lt;BR /&gt;debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1&lt;BR /&gt;debug2: kex_parse_kexinit: ssh-rsa,ssh-dss&lt;BR /&gt;debug2: kex_parse_kexinit: aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc&lt;BR /&gt;debug2: kex_parse_kexinit: aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc&lt;BR /&gt;debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96&lt;BR /&gt;debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96&lt;BR /&gt;debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib&lt;BR /&gt;debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib&lt;BR /&gt;debug2: kex_parse_kexinit:&lt;BR /&gt;debug2: kex_parse_kexinit:&lt;BR /&gt;debug2: kex_parse_kexinit: first_kex_follows 0&lt;BR /&gt;debug2: kex_parse_kexinit: reserved 0&lt;BR /&gt;debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1&lt;BR /&gt;debug2: kex_parse_kexinit: ssh-rsa,ssh-dss&lt;BR /&gt;debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se&lt;BR /&gt;debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se&lt;BR /&gt;debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96&lt;BR /&gt;debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96&lt;BR /&gt;debug2: kex_parse_kexinit: none,zlib&lt;BR /&gt;debug2: kex_parse_kexinit: none,zlib&lt;BR /&gt;debug2: kex_parse_kexinit:&lt;BR /&gt;debug2: kex_parse_kexinit:&lt;BR /&gt;debug2: kex_parse_kexinit: first_kex_follows 0&lt;BR /&gt;debug2: kex_parse_kexinit: reserved 0&lt;BR /&gt;debug2: mac_init: found hmac-sha1&lt;BR /&gt;debug1: kex: server-&amp;gt;client aes256-cbc hmac-sha1 none&lt;BR /&gt;debug2: mac_init: found hmac-sha1&lt;BR /&gt;debug1: kex: client-&amp;gt;server aes256-cbc hmac-sha1 none&lt;BR /&gt;debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024&amp;lt;4096&amp;lt;8192) sent&lt;BR /&gt;debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP&lt;BR /&gt;debug2: dh_gen_key: priv key bits set: 248/512&lt;BR /&gt;debug2: bits set: 2008/4095&lt;BR /&gt;debug1: SSH2_MSG_KEX_DH_GEX_INIT sent&lt;BR /&gt;debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY&lt;BR /&gt;debug3: check_host_in_hostfile: filename /h/data/global/EC/System/openssh/client/ssh_known_hosts&lt;BR /&gt;debug3: check_host_in_hostfile: match line 3&lt;BR /&gt;debug1: Host 'xxx.xx.xx.xxx' is known and matches the RSA host key.&lt;BR /&gt;debug1: Found key in /h/data/global/EC/System/openssh/client/ssh_known_hosts:3&lt;BR /&gt;debug2: bits set: 2055/4095&lt;BR /&gt;debug1: ssh_rsa_verify: signature correct&lt;BR /&gt;debug2: kex_derive_keys&lt;BR /&gt;debug2: set_newkeys: mode 1&lt;BR /&gt;debug1: SSH2_MSG_NEWKEYS sent&lt;BR /&gt;debug1: expecting SSH2_MSG_NEWKEYS&lt;BR /&gt;debug2: set_newkeys: mode 0&lt;BR /&gt;debug1: SSH2_MSG_NEWKEYS received&lt;BR /&gt;debug1: SSH2_MSG_SERVICE_REQUEST sent&lt;BR /&gt;debug2: service_accept: ssh-userauth&lt;BR /&gt;debug1: SSH2_MSG_SERVICE_ACCEPT received&lt;BR /&gt;debug2: key: /h/data/global/EC/System/openssh/client/id_rsa (40048920)&lt;BR /&gt;debug2: key: /h/data/global/EC/System/openssh/client/id_dsa (400489e0)&lt;BR /&gt;debug3: input_userauth_banner&lt;BR /&gt;                                               This is xxx.xx.xx.xxx&lt;BR /&gt;debug1: Authentications that can continue: publickey,password,keyboard-interactive&lt;BR /&gt;debug3: start over, passed a different list publickey,password,keyboard-interactive&lt;BR /&gt;debug3: preferred none&lt;BR /&gt;debug1: No more authentication methods to try.&lt;BR /&gt;Permission denied (publickey,password,keyboard-interactive).&lt;BR /&gt;Connection closed&lt;BR /&gt;%</description>
      <pubDate>Mon, 19 May 2008 19:31:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200900#M324680</guid>
      <dc:creator>Jonathan Grymes</dc:creator>
      <dc:date>2008-05-19T19:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200901#M324681</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;This looks like sshd ran out of authentication methods and denied access due to bad password.&lt;BR /&gt;&lt;BR /&gt;If it never prompted for a password then check the following:&lt;BR /&gt;1) Bug fix at &lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt;&lt;BR /&gt;2) /var/adm/syslog/syslog.log errors&lt;BR /&gt;3) Permission and ownership on the home directory, and .ssh directory. Anything the slightest bit out of place there and it won't work.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 19 May 2008 19:45:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200901#M324681</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2008-05-19T19:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200902#M324682</link>
      <description>Im not prompted for a password nor should I. publickey authentication is failing.</description>
      <pubDate>Mon, 19 May 2008 19:50:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200902#M324682</guid>
      <dc:creator>Jonathan Grymes</dc:creator>
      <dc:date>2008-05-19T19:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200903#M324683</link>
      <description>&lt;!--!*#--&gt;I'd start with a simple SSH rather than SFTP.&lt;BR /&gt;That removes one layer of potential&lt;BR /&gt;complexity.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; [...]&lt;BR /&gt;&amp;gt; debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_rsa.&lt;BR /&gt;&amp;gt; debug2: key_type_from_name: unknown key type '-----BEGIN'&lt;BR /&gt;&amp;gt; debug3: key_read: missing keytype&lt;BR /&gt;&amp;gt; debug3: key_read: missing whitespace&lt;BR /&gt;&amp;gt; debug3: key_read: missing whitespace&lt;BR /&gt;&amp;gt; [...]&lt;BR /&gt;&lt;BR /&gt;Perhaps there's a message here.  Where did&lt;BR /&gt;you make your key files?  Are they in SSH2&lt;BR /&gt;format or OpenSSH format?</description>
      <pubDate>Mon, 19 May 2008 20:03:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200903#M324683</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2008-05-19T20:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200904#M324684</link>
      <description>&amp;gt;  debug2: key_type_from_name: unknown key type '-----BEGIN'&lt;BR /&gt;&amp;gt; debug3: key_read: missing keytype&lt;BR /&gt;&amp;gt; debug3: key_read: missing whitespace&lt;BR /&gt;&amp;gt; debug3: key_read: missing whitespace&lt;BR /&gt; &lt;BR /&gt;I would say that your authorized_keys file on the HP-UX system is badly formed. There are 3 parts to a public key, the encryption type of the key, the key itself and an optional comment about the source of the public key. The most common error is pasting a copy of the public key using vi and forgetting to turn off word wrap and auto-indent. Each public key is *EXACTLY* one (long) line. You might have comments between keys (like ---BEGIN...) but they must be on separate lines. &lt;BR /&gt; &lt;BR /&gt;A correct DSA or RSA public key would look like this:&lt;BR /&gt; &lt;BR /&gt;ssh-dsa AAAAB3NzaC1kc.....5oprw== bill@mypc.home.com&lt;BR /&gt; &lt;BR /&gt;NOTE: there are some terminal emulators that do not generate a key-type (as in: ssh-rsa) and for the HP-UX version, it appears to be a requirement.</description>
      <pubDate>Tue, 20 May 2008 00:23:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200904#M324684</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2008-05-20T00:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200905#M324685</link>
      <description>&amp;gt; I would say that your authorized_keys file&lt;BR /&gt;&amp;gt; on the HP-UX system is badly formed.&lt;BR /&gt;&lt;BR /&gt;"authorized_keys", or the files named in the&lt;BR /&gt;error messages?  As I read this, the HP-UX&lt;BR /&gt;system is the client, and "authorized_keys"&lt;BR /&gt;is used at the server, isn't it?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;  This is xxx.xx.xx.xxx&lt;BR /&gt;&lt;BR /&gt;It's always good to induce confusion by&lt;BR /&gt;hiding useful info, but it does get annoying&lt;BR /&gt;when it's hidden in only some places.  Can we&lt;BR /&gt;assume that "xxx.xx.xx.xxx" is really&lt;BR /&gt;"162.58.35.198" everywhere?</description>
      <pubDate>Tue, 20 May 2008 03:02:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200905#M324685</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2008-05-20T03:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH public key  authentication Issue</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200906#M324686</link>
      <description>Resolved.  In ssh_config PreferredAuthentications was set to none. To resolve I changed PreferredAuthentications publickey,password,keyboard-interactive</description>
      <pubDate>Thu, 22 May 2008 15:23:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-public-key-authentication-issue/m-p/4200906#M324686</guid>
      <dc:creator>Jonathan Grymes</dc:creator>
      <dc:date>2008-05-22T15:23:52Z</dc:date>
    </item>
  </channel>
</rss>

