Weird SSH problem....

Hi,

I am trying to get SSH working for a user on our network. SSH works fine for me connecting to any of our servers. For one particular user it won’t work at all. Here is the output of ‘ssh -vvv serverName’

OpenSSH_4.3p2, OpenSSL 0.9.8e-fips-rhel5 01 Jul 2008                                    
debug1: Reading configuration data /etc/ssh/ssh_config                                  
debug1: Applying options for *                                                          
debug2: ssh_connect: needpriv 0                                                         
debug1: Connecting to server [1.1.1.1] port 22.                                          
debug1: Connection established.                                                         
debug1: identity file /path/to/users/home/.ssh/identity type 1          
debug3: Not a RSA1 key file /path/to/users/home/.ssh/id_rsa.            
debug2: key_type_from_name: unknown key type '-----BEGIN'                               
debug3: key_read: missing keytype                                                       
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace                                                    
debug3: key_read: missing whitespace
debug3: key_read: missing whitespace
debug2: key_type_from_name: unknown key type '-----END'                                                                                                               
debug3: key_read: missing keytype
debug1: identity file /path/to/users/home/.ssh/id_rsa type -1
debug1: identity file /path/to/users/home/.ssh/id_dsa type -1      
debug1: loaded 3 keys
debug1: Remote protocol version 2.0, remote software version Sun_SSH_1.1.2                                                                                            
debug1: no match:
Sun_SSH_1.1.2                                                                                                  
debug1: Enabling compatibility mode for protocol 2.0                                                                                                                  
debug1: Local version string SSH-2.0-OpenSSH_4.3
debug2: fd 3 setting O_NONBLOCK
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1                                                  
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr 
debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr 
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96 
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96 
debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib
debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib 
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit:
debug2: kex_parse_kexinit: first_kex_follows 0                                       
debug2: kex_parse_kexinit: reserved 0
debug2: kex_parse_kexinit: gss-group1-sha1-toWM5Slw5Ew8Mqkay+al2g==,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1                                     
debug2: kex_parse_kexinit: ssh-rsa,ssh-dss
debug2: kex_parse_kexinit: aes128-ctr,aes128-cbc,arcfour,3des-cbc,blowfish-cbc debug2: kex_parse_kexinit: aes128-ctr,aes128-cbc,arcfour,3des-cbc,blowfish-cbc
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-sha1-96,hmac-md5-96
debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,hmac-sha1-96,hmac-md5-96                                                                                                
debug2: kex_parse_kexinit: none,zlib
debug2: kex_parse_kexinit: none,zlib
debug2: kex_parse_kexinit: de-LU,en-GB,en-IE,fr,fr-BE,fr-FR,fr-LU,nl-BE,nl,nl-NL,i-default                                                                            
debug2: kex_parse_kexinit: de-LU,en-GB,en-IE,fr,fr-BE,fr-FR,fr-LU,nl-BE,nl,nl-NL,i-default                                                                            
debug2: kex_parse_kexinit: first_kex_follows 0                                                                                                                        
debug2: kex_parse_kexinit: reserved 0
debug2: mac_init: found hmac-md5
debug1: kex: server->client aes128-cbc hmac-md5 none                                                                                                                  
debug2: mac_init: found hmac-md5
debug1: kex: client->server aes128-cbc hmac-md5 none                                                                                                                  
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent                                                                                                              
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug2: dh_gen_key: priv key bits set: 126/256
debug2: bits set: 522/1024
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent 
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY 
debug3: check_host_in_hostfile: filename /path/to/users/home/.ssh/known_hosts                                                                         
debug3: check_host_in_hostfile: match line 3                                                                                                                          
debug3: check_host_in_hostfile: filename /path/to/users/home/.ssh/known_hosts                                                                         
debug3: check_host_in_hostfile: match line 3                                                                                                                          
debug1: Host 'server' is known and matches the RSA host key.                                                                                                             
debug1: Found key in /path/to/users/home/.ssh/known_hosts:3                                                                                           
debug2: bits set: 535/1024
debug1: ssh_rsa_verify: signature correct
debug2: kex_derive_keys
debug2: set_newkeys: mode 1                                                                                    
debug1: SSH2_MSG_NEWKEYS sent 
debug1: expecting SSH2_MSG_NEWKEYS  
debug2: set_newkeys: mode 0 
debug1: SSH2_MSG_NEWKEYS received
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug2: key: /path/to/users/home/.ssh/identity (0x2b35a1cac8c0)
debug2: key: /path/to/users/home/.ssh/id_rsa ((nil))
debug2: key: /path/to/users/home/.ssh/id_dsa ((nil))
debug1: Authentications that can continue: gssapi-keyex,gssapi-with-mic,publickey,password,keyboard-interactive
debug3: start over, passed a different list gssapi-keyex,gssapi-with-mic,publickey,password,keyboard-interactive
debug3: preferred gssapi-with-mic,publickey,keyboard-interactive,password
debug3: authmethod_lookup gssapi-with-mic
debug3: remaining preferred: publickey,keyboard-interactive,password
debug3: authmethod_is_enabled gssapi-with-mic
debug1: Next authentication method: gssapi-with-mic
debug3: Trying to reverse map address 1.1.1.1
debug1: Unspecified GSS failure.  Minor code may provide more information
Unknown code krb5 195
debug1: Unspecified GSS failure.  Minor code may provide more information
Unknown code krb5 195
debug1: Unspecified GSS failure.  Minor code may provide more information
Unknown code krb5 195
debug2: we did not send a packet, disable method
debug3: authmethod_lookup publickey
debug3: remaining preferred: keyboard-interactive,password
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug1: Offering public key: /path/to/users/home/.ssh/identity
debug3: send_pubkey_test
debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: gssapi-keyex,gssapi-with-mic,publickey,password,keyboard-interactive
debug1: Trying private key: /path/to/users/home/.ssh/id_rsa
debug1: read PEM private key done: type RSA
debug3: sign_and_send_pubkey
debug2: we sent a publickey packet, wait for reply
debug1: Authentications that can continue: gssapi-keyex,gssapi-with-mic,publickey,password,keyboard-interactive
debug1: Trying private key: /path/to/users/home/.ssh/id_dsa
debug3: no such identity: /path/to/users/home/.ssh/id_dsa
debug2: we did not send a packet, disable method
debug3: authmethod_lookup keyboard-interactive
debug3: remaining preferred: password
debug3: authmethod_is_enabled keyboard-interactive
debug1: Next authentication method: keyboard-interactive
debug2: userauth_kbdint
debug2: we sent a keyboard-interactive packet, wait for reply
debug2: input_userauth_info_req
debug2: input_userauth_info_req: num_prompts 1

The server never seems to respond to the line:

debug1: Trying private key: /path/to/users/home/.ssh/id_rsa
debug1: read PEM private key done: type RSA
debug3: sign_and_send_pubkey

If I compare it to a successful connection using my user id:

                                                                                                                 
debug3: remaining preferred: keyboard-interactive,password
debug3: authmethod_is_enabled publickey                   
debug1: Next authentication method: publickey             
debug1: Trying private key: /path/to/users/home/.ssh/identity
debug3: no such identity: /path/to/users/home/.ssh/identity  
debug1: Offering public key: /path/to/users/home/.ssh/id_rsa 
debug3: send_pubkey_test                                                     
debug2: we sent a publickey packet, wait for reply                           
debug1: Server accepts key: pkalg ssh-rsa blen 277                           
debug2: input_userauth_pk_ok: SHA1 fp 15:96:0f:7c:2e:5a:6e:bf:46:6e:4b:cb:ba:20:68:ab:18:80:b9:72
debug3: sign_and_send_pubkey                                                                     
debug1: read PEM private key done: type RSA                                                      
debug1: Authentication succeeded (publickey).                                                    
debug1: channel 0: new [client-session]                                                          
debug3: ssh_session2_open: channel_new: 0                                                        
debug2: channel 0: send open                                                                     
debug1: Entering interactive session.  

I have managed to get an SSH connection working when connecting from the user’s home account to my OpenSuse machine. It doesn’t work for any of our other servers though.

Any ideas greatly appreciated…

/jlar

It does complain about the key:

debug3: Not a RSA1 key file /path/to/users/home/.ssh/id_rsa.  

but I get that on successful connections too…

I finally got to the bottom of this thanks to this thread:

SSH Key Failure on One Account [Archive] - The macosxhints Forums

The permissions on the users home directory were 777… ssh doesn’t like that.

This fixed it:

chmod go-w ~/