Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #385 > unrolled thread

scp warning

Started byBob Tennent <BobT@cs.queensu.ca>
First post2011-06-24 18:07 +0000
Last post2011-06-24 19:33 +0000
Articles 4 — 2 participants

Back to article view | Back to comp.os.linux.networking


Contents

  scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 18:07 +0000
    Re: scp warning pk <pk@pk.invalid> - 2011-06-24 20:19 +0200
      Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:17 +0000
        Re: scp warning Bob Tennent <BobT@cs.queensu.ca> - 2011-06-24 19:33 +0000

#385 — scp warning

FromBob Tennent <BobT@cs.queensu.ca>
Date2011-06-24 18:07 +0000
Subjectscp warning
Message-ID<slrnj09kiq.ugg.BobT@linus.cs.queensu.ca>
scp has taken to producing messages of the form

  Address ...  maps to ..., but this does not map back to the address - 
  POSSIBLE BREAK-IN ATTEMPT!

How can I suppress such messages?

[toc] | [next] | [standalone]


#386

Frompk <pk@pk.invalid>
Date2011-06-24 20:19 +0200
Message-ID<iu2kor$2mk$1@speranza.aioe.org>
In reply to#385
On Fri, 24 Jun 2011 18:07:22 +0000 (UTC)
Bob Tennent <BobT@cs.queensu.ca> wrote:

> scp has taken to producing messages of the form
> 
>   Address ...  maps to ..., but this does not map back to the address - 
>   POSSIBLE BREAK-IN ATTEMPT!
> 
> How can I suppress such messages?

By fixing the DNS. 

Basically if you log in from 1.2.3.4, ssh does a reverse DNS lookup to find
the PTR record (ie, the domain name) associated to that address, and then
it does another forward lookup of the A address for that name, and check
that it corresponds to the IP address you are logging from (ie, 1.2.3.4 in
this example). If you fix the DNS to have those lookups match, the warning
will go away.

Alternatively, you could set

UseDNS no

in the sshd configuration file.

[toc] | [prev] | [next] | [standalone]


#387

FromBob Tennent <BobT@cs.queensu.ca>
Date2011-06-24 19:17 +0000
Message-ID<slrnj09oln.v5k.BobT@linus.cs.queensu.ca>
In reply to#386
On Fri, 24 Jun 2011 20:19:34 +0200, pk wrote:
 > On Fri, 24 Jun 2011 18:07:22 +0000 (UTC)
 > Bob Tennent <BobT@cs.queensu.ca> wrote:
 >
 >> scp has taken to producing messages of the form
 >> 
 >>   Address ...  maps to ..., but this does not map back to the address - 
 >>   POSSIBLE BREAK-IN ATTEMPT!
 >> 
 >> How can I suppress such messages?
 >
 > By fixing the DNS. 
 >
 > Basically if you log in from 1.2.3.4, ssh does a reverse DNS lookup to find
 > the PTR record (ie, the domain name) associated to that address, and then
 > it does another forward lookup of the A address for that name, and check
 > that it corresponds to the IP address you are logging from (ie, 1.2.3.4 in
 > this example). If you fix the DNS to have those lookups match, the warning
 > will go away.
 >

The complaints are about the IP address and domain of the remote site
which obtains a IP address by DHCP to which dyndns.org allows me to
associate a domain. 

 > Alternatively, you could set
 >
 > UseDNS no
 >
 > in the sshd configuration file.

Doesn't work (and, yes, I have re-started sshd).

Bob T.

[toc] | [prev] | [next] | [standalone]


#388

FromBob Tennent <BobT@cs.queensu.ca>
Date2011-06-24 19:33 +0000
Message-ID<slrnj09pjh.vf2.BobT@linus.cs.queensu.ca>
In reply to#387
On Fri, 24 Jun 2011 19:17:11 +0000 (UTC), Bob Tennent wrote:

 > > Alternatively, you could set
 > >
 > > UseDNS no
 > >
 > > in the sshd configuration file.
 >
 > Doesn't work (and, yes, I have re-started sshd).

What does work in sshd_config is

GSSAPIAuthentication no

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web