1763081 Members
3884 Online
108909 Solutions
New Discussion юеВ

trusted system

 
piyut_2
Frequent Advisor

trusted system

dear all,

I just changet to trusted system.when i tried to ssh only can with user root.the common user can't remote with ssh.what's wrong??

many thanks,

piyut
12 REPLIES 12
Gordon  Morrison
Trusted Contributor

Re: trusted system

Hi Piyut,
Do you mean you can't log in via ssh (as another user) without a password, or not at all? Does it say something like "can't verify remote host... are you sure you want to connect?" If so, answer "yes".
Is this a new ssh installation, or was ssh working on this host before?
Does telnet still work?
Are you sure that this user account is not locked/disabled? To re-enable it:
/usr/lbin/modprpw -k username

Also check the value of IgnoreUserKnownHosts in /opt/ssh/etc/sshd_config - If it's 'yes' that could be your problem
What does this button do?
piyut_2
Frequent Advisor

Re: trusted system

yes, i can't login via ssh as another user, only user root can login via ssh.before i changed to trusted system, another user can login via ssh.this user not locked.
piyut_2
Frequent Advisor

Re: trusted system

when i try to ssh to localhost:

# ssh prasz@localhost
prasz@localhost's password:
Connection to localhost closed by remote host.
Connection to localhost closed.
# ssh root@localhost
root@localhost's password:
Last successful login for root: Tue Mar 8 18:39:25 wib-7 2005 on pts/0
Last unsuccessful login for root: Tue Mar 8 17:40:05 wib-7 2005 on pts/ta
Last login: Tue Mar 8 18:39:25 2005 from 10.2.133.62
(c)Copyright 1983-2000 Hewlett-Packard Co., All Rights Reserved.
(c)Copyright 1979, 1980, 1983, 1985-1993 The Regents of the Univ. of California
(c)Copyright 1980, 1984, 1986 Novell, Inc.
(c)Copyright 1986-1992 Sun Microsystems, Inc.
(c)Copyright 1985, 1986, 1988 Massachusetts Institute of Technology
(c)Copyright 1989-1993 The Open Software Foundation, Inc.
(c)Copyright 1986 Digital Equipment Corp.
(c)Copyright 1990 Motorola, Inc.
(c)Copyright 1990, 1991, 1992 Cornell University
(c)Copyright 1989-1991 The University of Maryland
(c)Copyright 1988 Carnegie Mellon University
(c)Copyright 1991-2000 Mentat Inc.
(c)Copyright 1996 Morning Star Technologies, Inc.
(c)Copyright 1996 Progressive Systems, Inc.
(c)Copyright 1991-2000 Isogon Corporation, All Rights Reserved.


RESTRICTED RIGHTS LEGEND
Use, duplication, or disclosure by the U.S. Government is subject to
restrictions as set forth in sub-paragraph (c)(1)(ii) of the Rights in
Technical Data and Computer Software clause in DFARS 252.227-7013.

Hewlett-Packard Company
3000 Hanover Street
Palo Alto, CA 94304 U.S.A.

Rights for non-DOD U.S. Government Departments and Agencies are as set
forth in FAR 52.227-19(c)(1,2).
#


Gordon  Morrison
Trusted Contributor

Re: trusted system

Try ssh -v hostname
That should give you more output, and hopefully show why it's failing
You can also do ssh -vv or even ssh -vvv to get even more output.
What does this button do?
RAC_1
Honored Contributor

Re: trusted system

When you convert to trusted mode, all accounts will expire. Just do /usr/lbin/modprpw -V and you should be fine.
If not, then post ssh -vvv and sshd -ddd (from server side)

Anil
There is no substitute to HARDWORK
Gordon  Morrison
Trusted Contributor

Re: trusted system

> When you convert to trusted mode, all accounts will expire.

Woah!!! Talk about reading the small print!
Who wrote tsconvert? A lawyer?;o)
What does this button do?
piyut_2
Frequent Advisor

Re: trusted system

guys,

we must install :
1. OpenSSL_A.00.09.07-d.006_HP-UX_B.11.11_32+64.depot
2. T1471AA_A.03.71.000_HP-UX_B.11.11_32+64.depot

and all user can login via ssh.


thanks for all,

piyut
piyut_2
Frequent Advisor

Re: trusted system

oh god!!!

mount point / 98% after trusted system installed.this mount point always grow.how come???
Gordon  Morrison
Trusted Contributor

Re: trusted system

/tcb is where the trusted system files are installed, and that is by default on the root filesystem ( / )

Are /opt /var /tmp and /usr seperate filesystems? They should be.
What does this button do?