[opensuse-factory] lost ssh from 13.1 server, Re:New Tumbleweed snapshot 20160422 released!
* Ludwig Nussel <ludwig.nussel@suse.de> [04-28-16 21:42]:
Please note that this mail was generated by a script. The described changes are computed based on the x86_64 DVD. The full online repo contains too many changes to be listed here.
Please check the known defects of this snapshot before upgrading: https://openqa.opensuse.org/tests/overview?distri=opensuse&groupid=1&version=Tumbleweed&build=20160422
Packages changed: armagetron
After updating to 20160422, I can no longer ssh from my 13.1 server to my local Tw machines. I can ssh from the Tw machines into the server. 10:38 wahoo:~ > ssh -X -v paka@crash OpenSSH_6.2p2, OpenSSL 1.0.1k 8 Jan 2015 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 20: Applying options for * debug1: Connecting to crash [192.168.1.10] port 22. debug1: Connection established. debug1: identity file /home/paka/.ssh/id_rsa type -1 debug1: identity file /home/paka/.ssh/id_rsa-cert type -1 debug1: identity file /home/paka/.ssh/id_dsa type -1 debug1: identity file /home/paka/.ssh/id_dsa-cert type -1 debug1: identity file /home/paka/.ssh/id_ecdsa type -1 debug1: identity file /home/paka/.ssh/id_ecdsa-cert type -1 debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_6.2 debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1 debug1: match: OpenSSH_6.6.1 pat OpenSSH* debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: server->client aes128-ctr hmac-md5-etm@openssh.com none debug1: kex: client->server aes128-ctr hmac-md5-etm@openssh.com none debug1: sending SSH2_MSG_KEX_ECDH_INIT debug1: expecting SSH2_MSG_KEX_ECDH_REPLY Connection closed by 192.168.1.10 I have restarted ssh on both sides but no help. googling expecting SSH2_MSG_KEX_ECDH_REPLY shows much but doesn't appear to provide an intelligent solution. Changing MTU on either/both sides does not help, permissions appear correct on /etc/ssh/* I can ssh between Tw machines and between Tw machines into 13.1 server, but not from 13.1 server to *any* Tw machines. tks, -- (paka)Patrick Shanahan Plainfield, Indiana, USA @ptilopteri http://en.opensuse.org openSUSE Community Member facebook/ptilopteri http://wahoo.no-ip.org Photo Album: http://wahoo.no-ip.org/gallery2 Registered Linux User #207535 @ http://linuxcounter.net -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
On pátek 29. dubna 2016 10:42 Patrick Shanahan wrote:
After updating to 20160422, I can no longer ssh from my 13.1 server to my local Tw machines. I can ssh from the Tw machines into the server.
10:38 wahoo:~ > ssh -X -v paka@crash OpenSSH_6.2p2, OpenSSL 1.0.1k 8 Jan 2015 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 20: Applying options for * debug1: Connecting to crash [192.168.1.10] port 22. debug1: Connection established. debug1: identity file /home/paka/.ssh/id_rsa type -1 debug1: identity file /home/paka/.ssh/id_rsa-cert type -1 debug1: identity file /home/paka/.ssh/id_dsa type -1 debug1: identity file /home/paka/.ssh/id_dsa-cert type -1 debug1: identity file /home/paka/.ssh/id_ecdsa type -1 debug1: identity file /home/paka/.ssh/id_ecdsa-cert type -1 debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_6.2 debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1 debug1: match: OpenSSH_6.6.1 pat OpenSSH* debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: server->client aes128-ctr hmac-md5-etm@openssh.com none debug1: kex: client->server aes128-ctr hmac-md5-etm@openssh.com none debug1: sending SSH2_MSG_KEX_ECDH_INIT debug1: expecting SSH2_MSG_KEX_ECDH_REPLY Connection closed by 192.168.1.10
I have restarted ssh on both sides but no help.
I can ssh between Tw machines and between Tw machines into 13.1 server, but not from 13.1 server to *any* Tw machines.
https://bugzilla.suse.com/show_bug.cgi?id=977812 Michal Kubeček -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 10:49]:
On pátek 29. dubna 2016 10:42 Patrick Shanahan wrote:
After updating to 20160422, I can no longer ssh from my 13.1 server to my local Tw machines. I can ssh from the Tw machines into the server.
10:38 wahoo:~ > ssh -X -v paka@crash OpenSSH_6.2p2, OpenSSL 1.0.1k 8 Jan 2015 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 20: Applying options for * debug1: Connecting to crash [192.168.1.10] port 22. debug1: Connection established. debug1: identity file /home/paka/.ssh/id_rsa type -1 debug1: identity file /home/paka/.ssh/id_rsa-cert type -1 debug1: identity file /home/paka/.ssh/id_dsa type -1 debug1: identity file /home/paka/.ssh/id_dsa-cert type -1 debug1: identity file /home/paka/.ssh/id_ecdsa type -1 debug1: identity file /home/paka/.ssh/id_ecdsa-cert type -1 debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_6.2 debug1: Remote protocol version 2.0, remote software version OpenSSH_6.6.1 debug1: match: OpenSSH_6.6.1 pat OpenSSH* debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: server->client aes128-ctr hmac-md5-etm@openssh.com none debug1: kex: client->server aes128-ctr hmac-md5-etm@openssh.com none debug1: sending SSH2_MSG_KEX_ECDH_INIT debug1: expecting SSH2_MSG_KEX_ECDH_REPLY Connection closed by 192.168.1.10
I have restarted ssh on both sides but no help.
I can ssh between Tw machines and between Tw machines into 13.1 server, but not from 13.1 server to *any* Tw machines.
I would never have come close to solving this and google would not help. commenting out UsePrivilegeSeparation sandbox # Default for new installations. on the Tw machines solved for me. tks, much -- (paka)Patrick Shanahan Plainfield, Indiana, USA @ptilopteri http://en.opensuse.org openSUSE Community Member facebook/ptilopteri http://wahoo.no-ip.org Photo Album: http://wahoo.no-ip.org/gallery2 Registered Linux User #207535 @ http://linuxcounter.net -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
On pátek 29. dubna 2016 11:46 Patrick Shanahan wrote:
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 10:49]:
I would never have come close to solving this and google would not help.
commenting out UsePrivilegeSeparation sandbox # Default for new installations.
on the Tw machines solved for me.
Just don't forget to reenable it once an update fixing this bug is installed. :-) Michal Kubeček -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 12:00]:
On pátek 29. dubna 2016 11:46 Patrick Shanahan wrote:
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 10:49]:
I would never have come close to solving this and google would not help.
commenting out UsePrivilegeSeparation sandbox # Default for new installations.
on the Tw machines solved for me.
Just don't forget to reenable it once an update fixing this bug is installed. :-)
Made a notice to trigger on openssh update. tks -- (paka)Patrick Shanahan Plainfield, Indiana, USA @ptilopteri http://en.opensuse.org openSUSE Community Member facebook/ptilopteri http://wahoo.no-ip.org Photo Album: http://wahoo.no-ip.org/gallery2 Registered Linux User #207535 @ http://linuxcounter.net -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
On 04/29/2016 12:04 PM, Patrick Shanahan wrote:
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 12:00]:
On pátek 29. dubna 2016 11:46 Patrick Shanahan wrote:
* Michal Kubecek <mkubecek@suse.cz> [04-29-16 10:49]:
I would never have come close to solving this and google would not help.
commenting out UsePrivilegeSeparation sandbox # Default for new installations.
on the Tw machines solved for me.
Just don't forget to reenable it once an update fixing this bug is installed. :-)
Made a notice to trigger on openssh update. tks
Nice catch. -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org
participants (3)
-
Michal Kubecek
-
Patrick Shanahan
-
Roman Bysh