Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #387

Re: scp warning

From Bob Tennent <BobT@cs.queensu.ca>
Newsgroups comp.os.linux.networking
Subject Re: scp warning
Date 2011-06-24 19:17 +0000
Organization albasani.net
Message-ID <slrnj09oln.v5k.BobT@linus.cs.queensu.ca> (permalink)
References <slrnj09kiq.ugg.BobT@linus.cs.queensu.ca> <iu2kor$2mk$1@speranza.aioe.org>

Show all headers | View raw


On Fri, 24 Jun 2011 20:19:34 +0200, pk wrote:
 > On Fri, 24 Jun 2011 18:07:22 +0000 (UTC)
 > Bob Tennent <BobT@cs.queensu.ca> wrote:
 >
 >> scp has taken to producing messages of the form
 >> 
 >>   Address ...  maps to ..., but this does not map back to the address - 
 >>   POSSIBLE BREAK-IN ATTEMPT!
 >> 
 >> How can I suppress such messages?
 >
 > By fixing the DNS. 
 >
 > Basically if you log in from 1.2.3.4, ssh does a reverse DNS lookup to find
 > the PTR record (ie, the domain name) associated to that address, and then
 > it does another forward lookup of the A address for that name, and check
 > that it corresponds to the IP address you are logging from (ie, 1.2.3.4 in
 > this example). If you fix the DNS to have those lookups match, the warning
 > will go away.
 >

The complaints are about the IP address and domain of the remote site
which obtains a IP address by DHCP to which dyndns.org allows me to
associate a domain. 

 > Alternatively, you could set
 >
 > UseDNS no
 >
 > in the sshd configuration file.

Doesn't work (and, yes, I have re-started sshd).

Bob T.

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 18:07 +0000
  Re: scp warning pk <pk@pk.invalid> - 2011-06-24 20:19 +0200
    Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:17 +0000
      Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:33 +0000

csiph-web