Operating System - HP-UX
1862958 Members
2138 Online
110446 Solutions
New Discussion

Re: SSH public key authentication Issue

 
Jonathan Grymes
Frequent Advisor

SSH public key authentication Issue

Has anyone experienced this issue trying to initiate an sftp connection using public key authentication. Need resolution.

% sftp -vvv -F /h/data/global/EC/System/openssh/client/ssh_config [email protected]
Connecting to xxx.xx.xx.xxx...
OpenSSH_4.4p1-hpn12v11, OpenSSL 0.9.7l 28 Sep 2006
HP-UX Secure Shell-A.04.40.011, HP-UX Secure Shell version
debug1: Reading configuration data /h/data/global/EC/System/openssh/client/ssh_config
debug3: cipher ok: aes256-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: aes192-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: aes128-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: aes256-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: aes192-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: aes128-ctr [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: cipher ok: 3des-cbc [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug3: ciphers ok: [aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc]
debug2: mac_init: found hmac-sha1
debug3: mac ok: hmac-sha1 [hmac-sha1,hmac-sha1-96]
debug2: mac_init: found hmac-sha1-96
debug3: mac ok: hmac-sha1-96 [hmac-sha1,hmac-sha1-96]
debug3: macs ok: [hmac-sha1,hmac-sha1-96]
debug3: RNG is ready, skipping seeding
debug2: ssh_connect: needpriv 0
debug1: Connecting to 162.58.35.198 [162.58.35.198] port 22.
debug1: Connection established.
debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_rsa.
debug2: key_type_from_name: unknown key type '-----BEGIN'
debug3: key_read: missing keytype
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug2: key_type_from_name: unknown key type '-----END'
debug3: key_read: missing keytype
debug1: identity file /h/data/global/EC/System/openssh/client/id_rsa type 1
debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_dsa.
debug2: key_type_from_name: unknown key type '-----BEGIN'
debug3: key_read: missing keytype
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug2: key_type_from_name: unknown key type '-----END'
debug3: key_read: missing keytype
debug1: identity file /h/data/global/EC/System/openssh/client/id_dsa type 2
debug1: Remote protocol version 2.0, remote software version OpenSSH_3.6.1p2
debug1: match: OpenSSH_3.6.1p2 pat OpenSSH_3.*
debug1: Remote is NON-HPN aware
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_4.4p1-hpn12v11
debug2: fd 4 setting O_NONBLOCK
debug3: RNG is ready, skipping seeding
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc
debug2: kex_parse_kexinit: aes256-cbc,aes192-cbc,aes128-cbc,aes256-ctr,aes192-ctr,aes128-ctr,3des-cbc
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96
debug2: kex_parse_kexinit: hmac-sha1,hmac-sha1-96
debug2: kex_parse_kexinit: none,[email protected],zlib
debug2: kex_parse_kexinit: none,[email protected],zlib
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit: first_kex_follows 0
debug2: kex_parse_kexinit: reserved 0
debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,[email protected]
debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc,[email protected]
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,[email protected],hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: none,zlib
debug2: kex_parse_kexinit: none,zlib
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit: first_kex_follows 0
debug2: kex_parse_kexinit: reserved 0
debug2: mac_init: found hmac-sha1
debug1: kex: server->client aes256-cbc hmac-sha1 none
debug2: mac_init: found hmac-sha1
debug1: kex: client->server aes256-cbc hmac-sha1 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<4096<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug2: dh_gen_key: priv key bits set: 248/512
debug2: bits set: 2008/4095
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug3: check_host_in_hostfile: filename /h/data/global/EC/System/openssh/client/ssh_known_hosts
debug3: check_host_in_hostfile: match line 3
debug1: Host 'xxx.xx.xx.xxx' is known and matches the RSA host key.
debug1: Found key in /h/data/global/EC/System/openssh/client/ssh_known_hosts:3
debug2: bits set: 2055/4095
debug1: ssh_rsa_verify: signature correct
debug2: kex_derive_keys
debug2: set_newkeys: mode 1
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug2: set_newkeys: mode 0
debug1: SSH2_MSG_NEWKEYS received
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug2: key: /h/data/global/EC/System/openssh/client/id_rsa (40048920)
debug2: key: /h/data/global/EC/System/openssh/client/id_dsa (400489e0)
debug3: input_userauth_banner
This is xxx.xx.xx.xxx
debug1: Authentications that can continue: publickey,password,keyboard-interactive
debug3: start over, passed a different list publickey,password,keyboard-interactive
debug3: preferred none
debug1: No more authentication methods to try.
Permission denied (publickey,password,keyboard-interactive).
Connection closed
%
6 REPLIES 6
Steven E. Protter
Exalted Contributor

Re: SSH public key authentication Issue

Shalom,

This looks like sshd ran out of authentication methods and denied access due to bad password.

If it never prompted for a password then check the following:
1) Bug fix at http://software.hp.com
2) /var/adm/syslog/syslog.log errors
3) Permission and ownership on the home directory, and .ssh directory. Anything the slightest bit out of place there and it won't work.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Jonathan Grymes
Frequent Advisor

Re: SSH public key authentication Issue

Im not prompted for a password nor should I. publickey authentication is failing.
Steven Schweda
Honored Contributor

Re: SSH public key authentication Issue

I'd start with a simple SSH rather than SFTP.
That removes one layer of potential
complexity.

> [...]
> debug3: Not a RSA1 key file /h/data/global/EC/System/openssh/client/id_rsa.
> debug2: key_type_from_name: unknown key type '-----BEGIN'
> debug3: key_read: missing keytype
> debug3: key_read: missing whitespace
> debug3: key_read: missing whitespace
> [...]

Perhaps there's a message here. Where did
you make your key files? Are they in SSH2
format or OpenSSH format?
Bill Hassell
Honored Contributor

Re: SSH public key authentication Issue

> debug2: key_type_from_name: unknown key type '-----BEGIN'
> debug3: key_read: missing keytype
> debug3: key_read: missing whitespace
> debug3: key_read: missing whitespace

I would say that your authorized_keys file on the HP-UX system is badly formed. There are 3 parts to a public key, the encryption type of the key, the key itself and an optional comment about the source of the public key. The most common error is pasting a copy of the public key using vi and forgetting to turn off word wrap and auto-indent. Each public key is *EXACTLY* one (long) line. You might have comments between keys (like ---BEGIN...) but they must be on separate lines.

A correct DSA or RSA public key would look like this:

ssh-dsa AAAAB3NzaC1kc.....5oprw== [email protected]

NOTE: there are some terminal emulators that do not generate a key-type (as in: ssh-rsa) and for the HP-UX version, it appears to be a requirement.


Bill Hassell, sysadmin
Steven Schweda
Honored Contributor

Re: SSH public key authentication Issue

> I would say that your authorized_keys file
> on the HP-UX system is badly formed.

"authorized_keys", or the files named in the
error messages? As I read this, the HP-UX
system is the client, and "authorized_keys"
is used at the server, isn't it?

> This is xxx.xx.xx.xxx

It's always good to induce confusion by
hiding useful info, but it does get annoying
when it's hidden in only some places. Can we
assume that "xxx.xx.xx.xxx" is really
"162.58.35.198" everywhere?
Jonathan Grymes
Frequent Advisor

Re: SSH public key authentication Issue

Resolved. In ssh_config PreferredAuthentications was set to none. To resolve I changed PreferredAuthentications publickey,password,keyboard-interactive