LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-30-2005, 05:04 PM   #1
jburford
Member
 
Registered: Sep 2002
Distribution: Mandrake 10, IPCOP 1.4, SME Server 6, EvilEntity
Posts: 106

Rep: Reputation: 15
Unusual ssh cron message


I received the following email message from my mail server. The mail server is a SMEServer 6 system sitting in a DMZ behind an IPCOP router/firewall. It provides a webmail service, which can be accessed over ssl remotely, but pop access is only local.

I've never received messages from cron before, and have a very bad feeling about this....can anyone explain what is the likely cause, and how to investigate further?


Start message:

/etc/cron.daily/conf-mod_ssl:

2891 semi-random bytes loaded
Generating RSA private key, 1024 bit long modulus
.......++++++
.............................................++++++
e is 65537 (0x10001)
Using configuration from /usr/share/ssl/openssl.cnf
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:State or Province Name (full name) [Berkshire]:Locality Name (eg, city) [Newbury]:Organization Name (eg, company) [My Company Ltd]:Organizational Unit Name (eg, section) []:Common Name (eg, your name or your server's hostname) []:Email Address []:

End message

Any assistance appreciated!

Jim
 
Old 10-30-2005, 08:19 PM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Do a
Code:
cat /etc/cron.daily/conf-mod_ssl
Looks like the script is trying to regenerate an SSL key.
 
Old 10-30-2005, 08:28 PM   #3
jburford
Member
 
Registered: Sep 2002
Distribution: Mandrake 10, IPCOP 1.4, SME Server 6, EvilEntity
Posts: 106

Original Poster
Rep: Reputation: 15
What would trigger this? I have only logged on either to the console, or to web-based email. I have never received an email from the system before, and am interested in why - what does trigger cron to regenerate the ssh key? Is it usual or normal to do this on a regular basis?

James
 
Old 10-31-2005, 03:21 AM   #4
jburford
Member
 
Registered: Sep 2002
Distribution: Mandrake 10, IPCOP 1.4, SME Server 6, EvilEntity
Posts: 106

Original Poster
Rep: Reputation: 15
I got home and checked the box. The certificate is a year old, and has expired. SMEServer tried to generate a new one, and apparently failed (no idea why, I'll work on that!).

Anyway, not a train smash, but many thanks to TruckSmash for replying.

I had a few bad moments at work, looking at the message, thinking "this really does not look like a good day..."

Jim
 
Old 10-31-2005, 07:57 AM   #5
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Quote:
Originally posted by jburford
What would trigger this?
It ran b/c its in /etc/cron.daily. See man cron.
Quote:
Originally posted by jburford
what does trigger cron to regenerate the ssh key?
Note: it was regenerating an SSH key, not an SSL key. There's a difference.
Quote:
Originally posted by jburford
Is it usual or normal to do this on a regular basis?
Its neither "usual" or "unusual." It all depends on your system config.
Quote:
Originally posted by jburford
SMEServer tried to generate a new one, and apparently failed (no idea why, I'll work on that!).
It failed b/c generating an SSL cert is an interactive process, i.e. it requires user input. There was no user input b/c it ran from cron at 4AM, so it failed.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
unusual problem with SSH varunbihani Linux - General 1 07-09-2005 02:57 AM
cron 'test' message in my /var/log/messages file visaris Linux - Newbie 1 12-13-2004 04:03 PM
Worrying email message from cron merlininthewood Linux - Security 5 11-08-2004 05:48 AM
cron problem with message slick_willie Linux - General 10 05-01-2004 10:32 AM
cron job to print message to all ehpserver Linux - Newbie 1 02-28-2004 09:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration