[Bug 618068] New: ssh DISPLAY not set unless /etc/sshd/sshd_config `X11UseLocalhost no' set
http://bugzilla.novell.com/show_bug.cgi?id=618068 http://bugzilla.novell.com/show_bug.cgi?id=618068#c0 Summary: ssh DISPLAY not set unless /etc/sshd/sshd_config `X11UseLocalhost no' set Classification: openSUSE Product: openSUSE 11.3 Version: RC 1 Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: Network AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: pablo@blueoakdb.com QAContact: qa@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.4) Gecko/20100611 SUSE/3.6.4-6.1 Firefox/3.6.4 Howdy, ssh'ing from `openSUSE 11.1' to `openSUSE 11.3 RC1' results in the DISPLAY shell variable not being set with a stock `/etc/sshd/sshd_config' file. The work-around is to set in `/etc/sshd/sshd_config', `X11UseLocalhost no' The solution was found by googling around. Note: I'm not sure whether I should set the severity to `Normal' or `Major' As I mentioned above, I was able to come up with a work-around but I'm not sure whether enough people will google for a solution. You'd think a savvy enough SysAdmin would ... In order to help others in searching for this bug, I'll also include `/var/log/messages' entries found during `ssh'ing without the above setting: sshd[5538]: error: Failed to allocate internet-domain X11 display socket. Below are the `sshd' configuration values for the two machines: `openSUSE 11.3 RC1' =================== ROOT-root@zoom-37-[/root]: grep -v '^#' /etc/ssh/sshd_config | grep -v '^[ ]*$' PasswordAuthentication no UsePAM yes X11Forwarding yes X11UseLocalhost no Subsystem sftp /usr/lib/ssh/sftp-server AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL `openSUSE 11.1' =============== ROOT-root@oreo-1011-[/root]: grep -v '^#' /etc/ssh/sshd_config | grep -v '^[ ]*$' Protocol 2 PasswordAuthentication no UsePAM yes X11Forwarding yes Subsystem sftp /usr/lib/ssh/sftp-server AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL Reproducible: Always Steps to Reproduce: 1. Using stock '/etc/ssh/sshd_config', `ssh -Y' from `openSUSE 11.1' to `openSUSE 11.3 RC1' Note, it's possible to use `ssh -X' with the same result. 2. Type `xclock' to test whether DISPLAY is set correctly. Actual Results: As DISPLAY is not set in the shell, you cannot remotely view the X application. Expected Results: The X application should display correctly on the remote node. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c
yang xiaoyu
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c
Anna Bernathova
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c1
Anna Bernathova
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c2
Pablo Sanchez
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c3
Anna Bernathova
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c4
Anna Bernathova
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c5
Marius Tomaschewski
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c6
--- Comment #6 from Marius Tomaschewski
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c7
Reinhard Max
You're correct, I had shutdown `ipv6' support and that is the cause of when DISPLAY stop being set.
How did you disanble IPv6?
Is this an issue or are we getting ready for ipv6 support moving forward?
IPv6 should be mostly working by now. What was your reason to disable it? (In reply to comment #6)
What about to use just DISPLAY=:10.0 without "loopback" as hostname?
That way X clients would try to access the X server through the unix domain socket /tmp/.X11-unix/X10, which is not supported by sshd. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c8
--- Comment #8 from Marius Tomaschewski
(In reply to comment #6)
What about to use just DISPLAY=:10.0 without "loopback" as hostname?
That way X clients would try to access the X server through the unix domain socket /tmp/.X11-unix/X10, which is not supported by sshd.
Right. I've disabled it using "sysctl -w net.ipv6.conf.all.disable_ipv6=1" (just for a test) and it worked for me too. Generally I've ipv6 enabled all the time and it usually works fine (better), but I have a functional ipv6 network inclusive internet access... -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=618068
http://bugzilla.novell.com/show_bug.cgi?id=618068#c9
Pablo Sanchez
(In reply to comment #2)
You're correct, I had shutdown `ipv6' support and that is the cause of when DISPLAY stop being set.
How did you disanble IPv6?
Sorry for the late response. I have been on vacation. YaST > Network Settings > Global Options
Is this an issue or are we getting ready for ipv6 support moving forward?
IPv6 should be mostly working by now. What was your reason to disable it?
I had read in the past, DNS with IPv6 could `hang' so I've been disabling. Perhaps it's no longer an issue. -- Configure bugmail: http://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c
Anna Bernathova
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c10
Vadim Krevs
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c12
Maxim Vasilev
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c13
Petr Cerny
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c14
--- Comment #14 from Maxim Vasilev
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c
Maxim Vasilev
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c15
--- Comment #15 from Petr Cerny
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c16
Андрей Кувшинов
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c17
Stéphane DUFOUR
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c
kk zhang
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c18
a b
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c19
Michael Meeks
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c20
--- Comment #20 from Petr Cerny
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c21
--- Comment #21 from Michael Meeks
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c22
Jon Nelson
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c23
--- Comment #23 from Jon Nelson
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c24
Tristan Miller
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c25
Andrey Borzenkov
I experienced this problem after upgrading from openSUSE 11.4 to openSUSE 12.3.
Could you updated openssh package for 12.3: zypper ar obs://home:arvidjaar:bnc:712683/standard bnc712683 zypper refresh bnc712683 zypper dup -r bnc712683 Works for me, but I'm interested in some more extensive testing. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=618068
https://bugzilla.novell.com/show_bug.cgi?id=618068#c26
patrick shanahan
participants (1)
-
bugzilla_noreply@novell.com