LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-04-2014, 06:30 AM   #1
slackist
Member
 
Registered: Feb 2004
Location: Phuket
Distribution: Slackware 14.2 and Slackware Arm
Posts: 479

Rep: Reputation: 44
Help with understanding sshd log errors


Slackware 14.1, all up to date as per Slackware security mailing list.

Previously I used 2 programs on my Mac to access files on the Slackware machine, 1 uses sftp and the other scp.

Something I updated has made it so neither app can now connect, although I can still ssh into the box from a terminal on the same Mac without any problems.

Both the apps are up to date (and have had no updates since before the problem started), but I did update the Bash on the Mac because Apple didn't, but as I said ssh from a Bash prompt still works fine.

I am trying to nail down if the problem is from the Mac side or the Slack side, if it is Mac side I will ask for the thread to be closed and look for solutions in the correct section.

Here is what syslog says when the connections fail:

First, muCommander using sftp:
Code:
Dec  4 18:36:43 darkstar sshd[12545]: fatal: no matching cipher found: client blowfish-cbc,3des-cbc server aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com [preauth]
The above is when there is no Ciphers line in sshd_config, after googling I have tried adding a Ciphers line to sshd_config but it made no difference. The thing I think is odd is that the ciphers are all comma separated except for the bit that says 'server', is that normal from syslog? I have tried a Ciphers line with and without the server bit and with and without comma separating it but it makes no difference.

Second Komodo Edit using scp:
Code:
Dec  4 18:34:48 darkstar sshd[12516]: fatal: Unable to negotiate a key exchange method [preauth]
That's it! No amount of fiddling with password, username or port etc causes any other message, just that one as soon as the dialog box to enter the password to connect opens so it looks like it is failing before it really tries to start. Putting a file onto the Slack machine with scp from the terminal works fine

The only changes I can remember making to sshd_config were to set a different port, deny root login and permit login for only one specific username.

Last edited by slackist; 12-04-2014 at 06:32 AM.
 
Old 12-04-2014, 07:05 AM   #2
linosaurusroot
Member
 
Registered: Oct 2012
Distribution: OpenSuSE,RHEL,Fedora,OpenBSD
Posts: 982
Blog Entries: 2

Rep: Reputation: 244Reputation: 244Reputation: 244
Quote:
no matching cipher found: client blowfish-cbc,3des-cbc server aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com
no matching cipher found:

client provides list "blowfish-cbc,3des-cbc"

server provides list "aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-
poly1305@openssh.com"

No overlap between lists -> FAIL.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to have a log for sshd? xpucto Linux - Networking 4 06-03-2008 04:37 AM
Starting sshd: /etc/init.d/sshd: line 113: /usr/sbin/sshd: Permission denied sumanc Linux - Server 5 03-28-2008 04:59 AM
Log all sshd attempts hbar Debian 2 01-29-2008 03:53 PM
SSHD log? itz2000 Linux - Security 6 11-15-2005 08:39 AM
sshd log -am I in trouble? c_mitulescu Linux - Security 2 12-13-2004 05:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration