ssh login with keys failing :(

Top Page
Attachments:
Message as email
+ (text/plain)
Delete this message
Reply to this message
Author: Nathan England
Date:  
Subject: ssh login with keys failing :(
--=-C/LzuZHgcozJeDsIvUGd
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

The easiest way that I know how to do this, go to the machine you want
to login from.
as the user who will log into the other machine, type
ssh-keygen -t dsa
follow the prompts, do NOT give it a password.

Once it's done, it will create a file called, id_dsa.pub in your .ssh
directory, copy that file to the machine you want to ssh to, then cat it
into the .ssh/authorized_keys file on the machine you want to log in to.

Then try to ssh to it and it will not ask for a password.


On Thu, 2004-01-22 at 15:21, wrote:
> I am trying to login with ssh keys and it is failing; output below.=20
> What I would like to do is to set up a nightly cron job for rsync and
> have the server login with ssh with keys instead of using a
> username/password
>=20
>=20
> I have edited /etc/.ssh/ssh_config and set "RhostsAuthentication yes" on
> both systems and done at /etc/init.d/ssh restart so that the new setting
> would take effect. =20
>=20
> ssh -v -1 hostname
> OpenSSH_3.6.1p2 Debian 1:3.6.1p2-11, SSH protocols 1.5/2.0, OpenSSL 0x009=

0702f
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: Rhosts Authentication disabled, originating port will not be trus=

ted.
> debug1: Connecting to hostname [ip.address] port 22.
> debug1: Connection established.
> debug1: identity file /root/.ssh/identity type -1
> debug1: Remote protocol version 2.0, remote software version OpenSSH_3.6.=

1p2 Debian 1:3.6.1p2-11
> debug1: match: OpenSSH_3.6.1p2 Debian 1:3.6.1p2-11 pat OpenSSH*
> Protocol major versions differ: 1 vs. 2
> debug1: Calling cleanup 0x80623b0(0x0)
>=20
>=20
> version 2 output below
>=20
> ssh -v -2 hostname
> OpenSSH_3.6.1p2 Debian 1:3.6.1p2-11, SSH protocols 1.5/2.0, OpenSSL 0x009=

0702f
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: Rhosts Authentication disabled, originating port will not be trus=

ted.
> debug1: Connecting to hostname [ip.address] port 22.
> debug1: Connection established.
> debug1: identity file /root/.ssh/id_rsa type -1
> debug1: identity file /root/.ssh/id_dsa type -1
> debug1: Remote protocol version 2.0, remote software version OpenSSH_3.6.=

1p2 Debian 1:3.6.1p2-11
> debug1: match: OpenSSH_3.6.1p2 Debian 1:3.6.1p2-11 pat OpenSSH*
> debug1: Enabling compatibility mode for protocol 2.0
> debug1: Local version string SSH-2.0-OpenSSH_3.6.1p2 Debian 1:3.6.1p2-11
> debug1: SSH2_MSG_KEXINIT sent
> debug1: SSH2_MSG_KEXINIT received
> debug1: kex: server->client aes128-cbc hmac-md5 none
> debug1: kex: client->server aes128-cbc hmac-md5 none
> debug1: SSH2_MSG_KEX_DH_GEX_REQUEST sent
> debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
> debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
> debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
> debug1: Host 'hostname' is known and matches the RSA host key.
> debug1: Found key in /root/.ssh/known_hosts:4
> debug1: ssh_rsa_verify: signature correct
> debug1: SSH2_MSG_NEWKEYS sent
> debug1: expecting SSH2_MSG_NEWKEYS
> debug1: SSH2_MSG_NEWKEYS received
> debug1: SSH2_MSG_SERVICE_REQUEST sent
> debug1: SSH2_MSG_SERVICE_ACCEPT received
> debug1: Authentications that can continue: publickey,password,keyboard-in=

teractive
> debug1: Next authentication method: publickey
> debug1: Trying private key: /root/.ssh/id_rsa
> debug1: Trying private key: /root/.ssh/id_dsa
> debug1: Next authentication method: keyboard-interactive
> debug1: Authentications that can continue: publickey,password,keyboard-in=

teractive
> debug1: Next authentication method: password
> root@hostnames password:
>=20
>=20
>=20
> ---------------------------------------------------
> PLUG-discuss mailing list -
> To subscribe, unsubscribe, or to change you mail settings:
> http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss

--=20
Nathan England

Arcanum Linux !
nathan at the-arcanum.org
jabber id:

"A free society is one where it is safe to be unpopular."
--Adlai Stevenson


Registered Linux User #189789, Machine #106603
www.sincerechoice.org

--=-C/LzuZHgcozJeDsIvUGd
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQBAEFDQBSK6uOjZg9gRAjJzAKCJRohD2i213oeJnPxB+/ZafEkEkwCgrMlg
aXBXK4n6o8FD4V6/Lk1TSXo=
=IwOw
-----END PGP SIGNATURE-----

--=-C/LzuZHgcozJeDsIvUGd--