Operating System - HP-UX
1833744 Members
2690 Online
110063 Solutions
New Discussion

Re: putty to ssh client on 11.23 dropping login connections when showing banner

 
Don Mallory
Trusted Contributor

putty to ssh client on 11.23 dropping login connections when showing banner

Hi there,

I have a strange one. 11.23, new build, running Secure Shell A.05.00.013.

Default sshd has been configured as follows:

Protocol 2
LoginGraceTime 90
PermitRootLogin yes
PasswordAuthentication yes
KerberosAuthentication yes
GSSAPIAuthentication yes
GSSAPICleanupCredentials yes
UsePAM yes
X11Forwarding yes
X11UseLocalhost no
Banner /etc/issue
HPNDisabled yes
Subsystem sftp /opt/ssh/libexec/sftp-server


Logins from UX or Linux boxes via ssh are no problem. Banner is 2 lines, plain text, no more that 50 chars per line, only symbols are . and -.

When logging in with Putty 0.60, it gets to the username prompt, enter a username, ANY username and it drops the connection. Remove the bannerfile entry completely, and everything is okay.

Any ideas? Here's the output of sshd -dddd from the point of connection just prior to entering a username:

debug1: userauth-request for user root service ssh-connection method none
SSH: Server;Ltype: Authname;Remote: 13.22.1.32-3418;Name: root
debug1: attempt 0 failures 0
debug3: mm_getpwnamallow entering
debug3: mm_request_send entering: type 6
debug3: mm_getpwnamallow: waiting for MONITOR_ANS_PWNAM
debug3: monitor_read: checking request 6
debug3: mm_request_receive_expect entering: type 7
debug3: mm_answer_pwnamallow
debug3: mm_request_receive entering
debug3: Trying to reverse map address 13.22.1.32.
debug2: parse_server_config: config reprocess config len 449
debug1: Config token is protocol
debug1: Config token is logingracetime
debug1: Config token is permitrootlogin
debug1: Config token is passwordauthentication
debug1: Config token is kerberosauthentication
debug1: Config token is gssapiauthentication
debug1: Config token is gssapicleanupcredentials
debug1: Config token is usepam
debug1: Config token is x11forwarding
debug1: Config token is x11uselocalhost
debug1: Config token is banner
debug1: Config token is hpndisabled
debug1: Config token is subsystem
debug3: mm_answer_pwnamallow: sending MONITOR_ANS_PWNAM: 1
debug3: mm_request_send entering: type 7
debug2: monitor_read: 6 used once, disabling now
debug3: mm_request_receive entering
debug2: input_userauth_request: setting up authctxt for root
debug3: mm_start_pam entering
debug3: mm_request_send entering: type 45
debug3: mm_inform_authserv entering
debug3: monitor_read: checking request 45
debug3: mm_request_send entering: type 3
debug1: PAM: initializing for "root"
debug3: auth_allowed: method=none user=root
debug1: PAM: setting PAM_RHOST to "pc1234.domain.ca"
debug2: monitor_read: 45 used once, disabling now
debug3: Trying to reverse map address 13.22.1.32.
debug3: mm_request_receive enteridebug2: input_userauth_request: try method none
ng
debug3: mm_auth2_read_banner entering
debug3: monitor_read: checking request 3
debug3: mm_request_send entering: type 8
debug3: mm_answer_authserv: service=ssh-connection, style=
debug3: mm_request_receive_expect entering: type 9
debug3: mm_request_receive entering
debug2: monitor_read: 3 used once, disabling now
debug3: mm_request_receive entering
debug3: monitor_read: checking request 8
debug3: mm_request_send entering: type 9
debug2: monitor_read: 8 used once, disabling now
debug1: userauth_send_banner: sent
debug3: mm_request_receive entering
debug3: mm_auth_password entering
debug3: mm_request_send entering: type 10
debug3: mm_auth_password: waiting for MONITOR_ANS_AUTHPASSWORD
debug3: monitor_read: checking request 10
debug3: mm_request_receive_expect entering: type 11
debug3: mm_answer_authpassword: sdebug3: mm_request_receive entering
ending result 0
debug3: mm_request_send entering: type 11
debug3: mm_auth_password: user not authenticated
Failed none for root from 13.22.1.32 port 3418 ssh2
debug3: auth_allowed: method=publickey user=root
debug1: audit event euid 0 user root event 3 (AUTH_FAIL_NONE)
debug3: mm_request_receive entering
debug3: auth_allowed: method=gssapi-with-mic user=root
debug3: auth_allowed: method=password user=root
debug3: auth_allowed: method=keyboard-interactive user=root
debug1: do_cleanup
debug1: PAM: cleanup
debug3: PAM: sshpam_thread_cleanup entering
debug1: audit event euid 0 user root event 12 (CONNECTION_ABANDON)
1 REPLY 1
Don Mallory
Trusted Contributor

Re: putty to ssh client on 11.23 dropping login connections when showing banner

There's more to this. I'll open a different thread. Please remove this one.