<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Child process hanging and cannot be killed in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042857#M738003</link>
    <description>Rosli,&lt;BR /&gt;&lt;BR /&gt;This UsePrivilegeSeparation setting was introduced with HPUX SSH version 3.10.002.  It was done in connection with the security bulletin HPSBUX00195 &lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01001231-1" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01001231-1&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;Having said that, the Sec. Bull. doesn't give you a whole lot to base your decision on, which is normal for these things.&lt;BR /&gt;&lt;BR /&gt;I have seen this happen with ssh, but only with the 'batch' type logins on my machines.   The curious thing in your case is that the [priv] process (pid 7747 in your example) has a parent of init.  When this happens to me (PA and IA), the parent is always the sshd process itself, not init.  I am about to kill the process, either the [priv] process or the no tty process.  Is your ssh daemon being restarted on a regular basis or something like that?&lt;BR /&gt;&lt;BR /&gt;If you can get things to start listening to the kill, you can set something up that looks for 'sshd' and 'notty', and kill those off, then toss it into cron.&lt;BR /&gt;&lt;BR /&gt;Of course, you could also open an issue with HP, and complain about the 'feature'.&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;John&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 22 May 2007 12:47:52 GMT</pubDate>
    <dc:creator>John Payne_2</dc:creator>
    <dc:date>2007-05-22T12:47:52Z</dc:date>
    <item>
      <title>SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042853#M737999</link>
      <description>Hi experts, &lt;BR /&gt;I have a bunch of HP-UX Itanium boxes pre-installed with OpenSSH_3.7 with defaulted sshd_config. Recently my customer complained that when his user account did a batch SSH login every 10 mins, a child process is spawned. However after the account has logged off, the process still exists.even though the ssh login verbose mode shows the exit is clean (Exit Status 0). This caused performance degradation and may eventually lead to probably login limitation through port 22. After a while I fixed the issue by setting parameter UsePrivilegeSeparation in sshd_config to be a no and now the account does a proper logout and its child process left defunct. &lt;BR /&gt;Now, I have 1 concern and 1 problem. My concern is by putting UsePrivilegeSeparation's argument to no, there will be no security against corrupted/malicious privilege escalation. Anyone knows what is the risk &amp;amp; mitigating factors? &lt;BR /&gt;My problem is I cannot kill the defunct processes from the previous logins. A reboot will clean up the hanging processes but most being Production boxes, I am looking for alternatives. &lt;BR /&gt;&lt;BR /&gt;Some of the problem's synopsis;&lt;BR /&gt;$ ps -ef| grep 7747&lt;BR /&gt;    root  7747     1  0  Apr 15  ?         0:00 sshd: sascoll [priv]&lt;BR /&gt; sascoll  7750  7747  0  Apr 15  ?         0:00 sshd: sascoll@notty&lt;BR /&gt;&lt;BR /&gt;This is just one of the many defunct processes which can't be killed even as root.&lt;BR /&gt;&lt;BR /&gt;Finally, could the problem be a bug in the SSH version? Anyone had this problem before?</description>
      <pubDate>Thu, 26 Apr 2007 19:36:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042853#M737999</guid>
      <dc:creator>Rosli Osman</dc:creator>
      <dc:date>2007-04-26T19:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042854#M738000</link>
      <description>Hi Rosli,&lt;BR /&gt;&lt;BR /&gt;I'm hitting your thread, cause there were no responses on this.&lt;BR /&gt;&lt;BR /&gt;I'm getting similar on my 11.11 box(s) with Secure Shell 4.20.004 installed.&lt;BR /&gt;&lt;BR /&gt;Searching patch database and so far not finding any concrete answer..........&lt;BR /&gt;&lt;BR /&gt;Hoping someone else might have some insights on this irritation.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Rita</description>
      <pubDate>Tue, 22 May 2007 08:15:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042854#M738000</guid>
      <dc:creator>Rita C Workman</dc:creator>
      <dc:date>2007-05-22T08:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042855#M738001</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt;&lt;BR /&gt;Search: Secure Shell&lt;BR /&gt;&lt;BR /&gt;This could be just bad code. There are security flaws in your ssh version anyway, more than enough reason to update.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 22 May 2007 08:29:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042855#M738001</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-05-22T08:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042856#M738002</link>
      <description>Hey Stephen,&lt;BR /&gt;&lt;BR /&gt;Well I'm at 4.20 and they're at 3.7.  Only seeing our problem on our 7410 PARisc, while they see it on their Itanium.&lt;BR /&gt;&lt;BR /&gt;Still haven't figured out why........&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Rita</description>
      <pubDate>Tue, 22 May 2007 11:21:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042856#M738002</guid>
      <dc:creator>Rita C Workman</dc:creator>
      <dc:date>2007-05-22T11:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042857#M738003</link>
      <description>Rosli,&lt;BR /&gt;&lt;BR /&gt;This UsePrivilegeSeparation setting was introduced with HPUX SSH version 3.10.002.  It was done in connection with the security bulletin HPSBUX00195 &lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01001231-1" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01001231-1&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;Having said that, the Sec. Bull. doesn't give you a whole lot to base your decision on, which is normal for these things.&lt;BR /&gt;&lt;BR /&gt;I have seen this happen with ssh, but only with the 'batch' type logins on my machines.   The curious thing in your case is that the [priv] process (pid 7747 in your example) has a parent of init.  When this happens to me (PA and IA), the parent is always the sshd process itself, not init.  I am about to kill the process, either the [priv] process or the no tty process.  Is your ssh daemon being restarted on a regular basis or something like that?&lt;BR /&gt;&lt;BR /&gt;If you can get things to start listening to the kill, you can set something up that looks for 'sshd' and 'notty', and kill those off, then toss it into cron.&lt;BR /&gt;&lt;BR /&gt;Of course, you could also open an issue with HP, and complain about the 'feature'.&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;John&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 May 2007 12:47:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042857#M738003</guid>
      <dc:creator>John Payne_2</dc:creator>
      <dc:date>2007-05-22T12:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042858#M738004</link>
      <description>"I am about to kill the process"&lt;BR /&gt;&lt;BR /&gt;should read&lt;BR /&gt;&lt;BR /&gt;"I am able to kill the process"&lt;BR /&gt;&lt;BR /&gt;Sorry.&lt;BR /&gt;John</description>
      <pubDate>Tue, 22 May 2007 12:49:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042858#M738004</guid>
      <dc:creator>John Payne_2</dc:creator>
      <dc:date>2007-05-22T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042859#M738005</link>
      <description>Thanks Rita for reigniting this thread. &lt;BR /&gt;Yup John, it is strange that the processes are spawned from init (pid 1), instead of sshd itself. This I could not explain.  &lt;BR /&gt;I could not replicate the issue anymore whether the SSH daemon started everytime a batch login took place (it looks likely though, with all those processes having different pids).&lt;BR /&gt;But until today I still could not do a kill to those defunct processes.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 23 May 2007 00:37:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042859#M738005</guid>
      <dc:creator>Rosli Osman</dc:creator>
      <dc:date>2007-05-23T00:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042860#M738006</link>
      <description>Hi.&lt;BR /&gt;&lt;BR /&gt;We have had a similar problem on some (but not all) of our servers as well which we battled to solve. In our case though the server was a Red Hat Linux server and the client an HP-UX 11i v1 PA-RISC server. It appeared that the client wasn't terminating properly.  We replaced both servers before we resolved the issue, and we are no longer experiencing the problem.&lt;BR /&gt;&lt;BR /&gt;Does netstat give any indication of the status of of the connection (like a long TIME_WAIT2 perhaps?)&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Andrew Y&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 23 May 2007 01:50:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042860#M738006</guid>
      <dc:creator>Andrew Young_2</dc:creator>
      <dc:date>2007-05-23T01:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042861#M738007</link>
      <description>You aren't running ssh through inetd are you?  That's the only case I can think of where sshd itself could be spawned each time the connection occurs.  Otherwise, sshd should just be running all the time, listening for connections.  (One of the problems with running sshd from inetd is the key generation that occurs on startup)&lt;BR /&gt;&lt;BR /&gt;Anyway, does that mean you can suddenly kill these procs?  Did something change to allow this?</description>
      <pubDate>Wed, 23 May 2007 01:50:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042861#M738007</guid>
      <dc:creator>John Payne_2</dc:creator>
      <dc:date>2007-05-23T01:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042862#M738008</link>
      <description>I suspect the problem is more system than application (ssh).&lt;BR /&gt;I have fixed the initial problem by setting the parameter UsePrivilegeSeparation to no.&lt;BR /&gt;And based on feedback from experts, i ought to upgrade to higher version of SSH. That is already in the pipeline.&lt;BR /&gt;&lt;BR /&gt;This leaves only one irritation, as Rita has correctly indicated.&lt;BR /&gt;&lt;BR /&gt;From my example above, I can send kill signal to "priv" process but since pid 7747 is no longer around anymore, the "notty" process will indicate its ppid as 1. This "notty" process cannot be killed even as root or sascoll and I have 87 of such processes in my machine.&lt;BR /&gt;&lt;BR /&gt;netstat does not show any anomalies and sshd is always running at its full path, not from inetd.</description>
      <pubDate>Wed, 23 May 2007 03:41:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042862#M738008</guid>
      <dc:creator>Rosli Osman</dc:creator>
      <dc:date>2007-05-23T03:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042863#M738009</link>
      <description>No solution neither any reply. Closing thread</description>
      <pubDate>Mon, 18 Jun 2007 12:29:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042863#M738009</guid>
      <dc:creator>Rosli Osman</dc:creator>
      <dc:date>2007-06-18T12:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042864#M738010</link>
      <description>just thought I'd check - any update/resolution on this ssh issue?</description>
      <pubDate>Tue, 24 Jul 2007 11:35:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042864#M738010</guid>
      <dc:creator>Michelle Weiss</dc:creator>
      <dc:date>2007-07-24T11:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Child process hanging and cannot be killed</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042865#M738011</link>
      <description>I was told that this is most likely related to a known problem when a background process is launched from a ssh login session.&lt;BR /&gt;&lt;BR /&gt;Please see the following links for a description of the known problem and some workarounds.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.openssh.com/faq.html#3.10" target="_blank"&gt;http://www.openssh.com/faq.html#3.10&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://bugzilla.mindrot.org/show_bug.cgi?id=52" target="_blank"&gt;http://bugzilla.mindrot.org/show_bug.cgi?id=52&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Jul 2007 19:25:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-child-process-hanging-and-cannot-be-killed/m-p/5042865#M738011</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2007-07-24T19:25:05Z</dc:date>
    </item>
  </channel>
</rss>

