Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #385 > unrolled thread
| Started by | Bob Tennent <BobT@cs.queensu.ca> |
|---|---|
| First post | 2011-06-24 18:07 +0000 |
| Last post | 2011-06-24 19:33 +0000 |
| Articles | 4 — 2 participants |
Back to article view | Back to comp.os.linux.networking
scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 18:07 +0000
Re: scp warning pk <pk@pk.invalid> - 2011-06-24 20:19 +0200
Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:17 +0000
Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:33 +0000
| From | Bob Tennent <BobT@cs.queensu.ca> |
|---|---|
| Date | 2011-06-24 18:07 +0000 |
| Subject | scp warning |
| Message-ID | <slrnj09kiq.ugg.BobT@linus.cs.queensu.ca> |
scp has taken to producing messages of the form Address ... maps to ..., but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! How can I suppress such messages?
[toc] | [next] | [standalone]
| From | pk <pk@pk.invalid> |
|---|---|
| Date | 2011-06-24 20:19 +0200 |
| Message-ID | <iu2kor$2mk$1@speranza.aioe.org> |
| In reply to | #385 |
On Fri, 24 Jun 2011 18:07:22 +0000 (UTC) Bob Tennent <BobT@cs.queensu.ca> wrote: > scp has taken to producing messages of the form > > Address ... maps to ..., but this does not map back to the address - > POSSIBLE BREAK-IN ATTEMPT! > > How can I suppress such messages? By fixing the DNS. Basically if you log in from 1.2.3.4, ssh does a reverse DNS lookup to find the PTR record (ie, the domain name) associated to that address, and then it does another forward lookup of the A address for that name, and check that it corresponds to the IP address you are logging from (ie, 1.2.3.4 in this example). If you fix the DNS to have those lookups match, the warning will go away. Alternatively, you could set UseDNS no in the sshd configuration file.
[toc] | [prev] | [next] | [standalone]
| From | Bob Tennent <BobT@cs.queensu.ca> |
|---|---|
| Date | 2011-06-24 19:17 +0000 |
| Message-ID | <slrnj09oln.v5k.BobT@linus.cs.queensu.ca> |
| In reply to | #386 |
On Fri, 24 Jun 2011 20:19:34 +0200, pk wrote: > On Fri, 24 Jun 2011 18:07:22 +0000 (UTC) > Bob Tennent <BobT@cs.queensu.ca> wrote: > >> scp has taken to producing messages of the form >> >> Address ... maps to ..., but this does not map back to the address - >> POSSIBLE BREAK-IN ATTEMPT! >> >> How can I suppress such messages? > > By fixing the DNS. > > Basically if you log in from 1.2.3.4, ssh does a reverse DNS lookup to find > the PTR record (ie, the domain name) associated to that address, and then > it does another forward lookup of the A address for that name, and check > that it corresponds to the IP address you are logging from (ie, 1.2.3.4 in > this example). If you fix the DNS to have those lookups match, the warning > will go away. > The complaints are about the IP address and domain of the remote site which obtains a IP address by DHCP to which dyndns.org allows me to associate a domain. > Alternatively, you could set > > UseDNS no > > in the sshd configuration file. Doesn't work (and, yes, I have re-started sshd). Bob T.
[toc] | [prev] | [next] | [standalone]
| From | Bob Tennent <BobT@cs.queensu.ca> |
|---|---|
| Date | 2011-06-24 19:33 +0000 |
| Message-ID | <slrnj09pjh.vf2.BobT@linus.cs.queensu.ca> |
| In reply to | #387 |
On Fri, 24 Jun 2011 19:17:11 +0000 (UTC), Bob Tennent wrote: > > Alternatively, you could set > > > > UseDNS no > > > > in the sshd configuration file. > > Doesn't work (and, yes, I have re-started sshd). What does work in sshd_config is GSSAPIAuthentication no
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web