Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #263285 > unrolled thread
| Started by | fxkl47BF@protonmail.com |
|---|---|
| First post | 2023-11-09 16:10 +0100 |
| Last post | 2023-11-10 01:00 +0100 |
| Articles | 18 — 9 participants |
Back to article view | Back to linux.debian.user
upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 16:10 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Greg Wooledge <greg@wooledge.org> - 2023-11-09 17:50 +0100
Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 17:50 +0100
Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 18:10 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Greg Wooledge <greg@wooledge.org> - 2023-11-09 19:10 +0100
Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 19:40 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Michael <ml@hemathor.de> - 2023-11-10 11:10 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Vincent Lefevre <vincent@vinc17.net> - 2023-11-10 15:50 +0100
Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-10 16:40 +0100
Re: upgrade to bookworm broke ssh x11 forwarding David Wright <deblis@lionunicorn.co.uk> - 2023-11-10 17:20 +0100
Re: upgrade to bookworm broke ssh x11 forwarding <tomas@tuxteam.de> - 2023-11-10 18:50 +0100
Re: upgrade to bookworm broke ssh x11 forwarding tomas@tuxteam.de - 2023-11-10 19:30 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Dan Ritter <dsr@randomstring.org> - 2023-11-10 19:30 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Vincent Lefevre <vincent@vinc17.net> - 2023-11-13 11:20 +0100
Re: upgrade to bookworm broke ssh x11 forwarding <tomas@tuxteam.de> - 2023-11-13 11:20 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Jeffrey Walton <noloader@gmail.com> - 2023-11-09 19:30 +0100
Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 19:40 +0100
Re: upgrade to bookworm broke ssh x11 forwarding Jeffrey Walton <noloader@gmail.com> - 2023-11-10 01:00 +0100
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-09 16:10 +0100 |
| Subject | upgrade to bookworm broke ssh x11 forwarding |
| Message-ID | <HyePn-4fZl-1@gated-at.bofh.it> |
i upgraded from bullseye to bookworm with no problems when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails debug1: Requesting X11 forwarding with authentication spoofing. debug1: Sending environment. debug1: Sending env LANG = en_US.UTF-8 debug1: Sending env LC_ALL = en_US.UTF-8 X11 forwarding request failed on channel 0 the .Xauthority file is not updated is there new security or configuration
[toc] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2023-11-09 17:50 +0100 |
| Message-ID | <Hygo9-4gJ5-3@gated-at.bofh.it> |
| In reply to | #263285 |
On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
> i upgraded from bullseye to bookworm with no problems
> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
>
> debug1: Requesting X11 forwarding with authentication spoofing.
> debug1: Sending environment.
> debug1: Sending env LANG = en_US.UTF-8
> debug1: Sending env LC_ALL = en_US.UTF-8
> X11 forwarding request failed on channel 0
>
> the .Xauthority file is not updated
> is there new security or configuration
On the server, run:
grep X11 /etc/ssh/sshd_config
That should tell you whether X11Forwarding and its related options have
been disabled.
[toc] | [prev] | [next] | [standalone]
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-09 17:50 +0100 |
| Message-ID | <Hygo9-4gJ5-9@gated-at.bofh.it> |
| In reply to | #263291 |
On Thu, 9 Nov 2023, Greg Wooledge wrote: > On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote: >> i upgraded from bullseye to bookworm with no problems >> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails >> >> debug1: Requesting X11 forwarding with authentication spoofing. >> debug1: Sending environment. >> debug1: Sending env LANG = en_US.UTF-8 >> debug1: Sending env LC_ALL = en_US.UTF-8 >> X11 forwarding request failed on channel 0 >> >> the .Xauthority file is not updated >> is there new security or configuration > > On the server, run: > > grep X11 /etc/ssh/sshd_config > > That should tell you whether X11Forwarding and its related options have > been disabled. > $ grep X11 /etc/ssh/sshd_config X11Forwarding yes
[toc] | [prev] | [next] | [standalone]
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-09 18:10 +0100 |
| Message-ID | <HygHv-4h4N-3@gated-at.bofh.it> |
| In reply to | #263292 |
On Thu, 9 Nov 2023, fxkl47BF@protonmail.com wrote: > On Thu, 9 Nov 2023, Greg Wooledge wrote: > >> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote: >>> i upgraded from bullseye to bookworm with no problems >>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails >>> >>> debug1: Requesting X11 forwarding with authentication spoofing. >>> debug1: Sending environment. >>> debug1: Sending env LANG = en_US.UTF-8 >>> debug1: Sending env LC_ALL = en_US.UTF-8 >>> X11 forwarding request failed on channel 0 >>> >>> the .Xauthority file is not updated >>> is there new security or configuration >> >> On the server, run: >> >> grep X11 /etc/ssh/sshd_config >> >> That should tell you whether X11Forwarding and its related options have >> been disabled. >> > > $ grep X11 /etc/ssh/sshd_config > X11Forwarding yes > > now it makes a bit more sense sshd isn't running for some reason the upgrade switched to dropbear is this a new thing for bookworm is there a reason i shouldn't disable dropbear and use sshd
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2023-11-09 19:10 +0100 |
| Message-ID | <HyhDA-4hCV-5@gated-at.bofh.it> |
| In reply to | #263294 |
On Thu, Nov 09, 2023 at 04:59:32PM +0000, fxkl47BF@protonmail.com wrote: > now it makes a bit more sense > sshd isn't running > for some reason the upgrade switched to dropbear > is this a new thing for bookworm > is there a reason i shouldn't disable dropbear and use sshd No, this is not a normal phenomenon for bookworm upgrades. I've never heard of it happening to anyone before. You should be able to reinstall openssh-server and remove dropbear and get back to normal, unless there's something else unusual in your package set. As this situation is (AFAIK) unique to your system, you'll have to be the one to try it and see what happens.
[toc] | [prev] | [next] | [standalone]
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-09 19:40 +0100 |
| Message-ID | <Hyi6B-4hN1-3@gated-at.bofh.it> |
| In reply to | #263296 |
On Thu, 9 Nov 2023, Greg Wooledge wrote: > On Thu, Nov 09, 2023 at 04:59:32PM +0000, fxkl47BF@protonmail.com wrote: >> now it makes a bit more sense >> sshd isn't running >> for some reason the upgrade switched to dropbear >> is this a new thing for bookworm >> is there a reason i shouldn't disable dropbear and use sshd > > No, this is not a normal phenomenon for bookworm upgrades. I've never > heard of it happening to anyone before. > > You should be able to reinstall openssh-server and remove dropbear > and get back to normal, unless there's something else unusual in > your package set. As this situation is (AFAIK) unique to your system, > you'll have to be the one to try it and see what happens. > openssh was installed just not running i stopped and disabled dropbear and started sshd all is right for now thanks
[toc] | [prev] | [next] | [standalone]
| From | Michael <ml@hemathor.de> |
|---|---|
| Date | 2023-11-10 11:10 +0100 |
| Message-ID | <HywCB-4qPH-5@gated-at.bofh.it> |
| In reply to | #263296 |
On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > No, this is not a normal phenomenon for bookworm upgrades. I've never > heard of it happening to anyone before. i disagree. i had the same problem b/c i also had dropbear installed. for some reason the dropbear daemon is started first in bookworm, so port 22 was already in use when sshd was started. reading the log file (aka systemd-journal) was very enlightening. a simple systemctl stop dropbear.service systemctl disable dropbear.service systemctl start ssh.service was enough to solve the problem. of course, one needs access to the console... greetings...
[toc] | [prev] | [next] | [standalone]
| From | Vincent Lefevre <vincent@vinc17.net> |
|---|---|
| Date | 2023-11-10 15:50 +0100 |
| Message-ID | <HyAZz-4teJ-5@gated-at.bofh.it> |
| In reply to | #263327 |
On 2023-11-10 10:57:21 +0100, Michael wrote: > On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > > No, this is not a normal phenomenon for bookworm upgrades. I've never > > heard of it happening to anyone before. > > i disagree. i had the same problem b/c i also had dropbear installed. It would be interesting to know why dropbear got installed (if openssh-server was already installed, this is rather surprising), e.g. with "aptitude why dropbear". -- Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)
[toc] | [prev] | [next] | [standalone]
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-10 16:40 +0100 |
| Message-ID | <HyBLX-4tJT-1@gated-at.bofh.it> |
| In reply to | #263335 |
On Fri, 10 Nov 2023, Vincent Lefevre wrote: > On 2023-11-10 10:57:21 +0100, Michael wrote: >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: >>> No, this is not a normal phenomenon for bookworm upgrades. I've never >>> heard of it happening to anyone before. >> >> i disagree. i had the same problem b/c i also had dropbear installed. > > It would be interesting to know why dropbear got installed at sometime in the distance past i thought it would be handy my initial ramdisk is set up so i can remotely unlock the filesystems
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2023-11-10 17:20 +0100 |
| Message-ID | <HyCoF-4uck-1@gated-at.bofh.it> |
| In reply to | #263336 |
On Fri 10 Nov 2023 at 15:32:53 (+0000), fxkl47BF@protonmail.com wrote: > On Fri, 10 Nov 2023, Vincent Lefevre wrote: > > > On 2023-11-10 10:57:21 +0100, Michael wrote: > >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > >>> No, this is not a normal phenomenon for bookworm upgrades. I've never > >>> heard of it happening to anyone before. > >> > >> i disagree. i had the same problem b/c i also had dropbear installed. > > > > It would be interesting to know why dropbear got installed > > at sometime in the distance past i thought it would be handy > my initial ramdisk is set up so i can remotely unlock the filesystems You may have been relying on a race condition as to whether openssh or dropbear started first, and were just lucky in bullseye. The OP's "for some reason the upgrade switched to dropbear" is somewhat ambiguous, but it looks like the same problem. Perhaps Greg interpreted that "switched to" as meaning "installed as a dependency". Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-11-10 18:50 +0100 |
| Message-ID | <HyDNL-4uTF-1@gated-at.bofh.it> |
| In reply to | #263336 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Nov 10, 2023 at 03:32:53PM +0000, fxkl47BF@protonmail.com wrote: > On Fri, 10 Nov 2023, Vincent Lefevre wrote: > > > On 2023-11-10 10:57:21 +0100, Michael wrote: > >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > >>> No, this is not a normal phenomenon for bookworm upgrades. I've never > >>> heard of it happening to anyone before. > >> > >> i disagree. i had the same problem b/c i also had dropbear installed. > > > > It would be interesting to know why dropbear got installed > > at sometime in the distance past i thought it would be handy > my initial ramdisk is set up so i can remotely unlock the filesystems Wait a minute: dropbear is supposed to run in the initramfs, while sshd will be active afterwards, after pivot-root and all that, right? Then I don't quite get why they should collide at all. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | tomas@tuxteam.de |
|---|---|
| Date | 2023-11-10 19:30 +0100 |
| Message-ID | <HyEqt-4vln-5@gated-at.bofh.it> |
| In reply to | #263340 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Nov 10, 2023 at 01:01:28PM -0500, Dan Ritter wrote: > tomas@tuxteam.de wrote: [...] > > Wait a minute: dropbear is supposed to run in the initramfs, while > > sshd will be active afterwards, after pivot-root and all that, right? > > > > Then I don't quite get why they should collide at all. > > Because dropbear *can* be run as an ordinary sshd, and some > people do. Ugh. Re-reading I realise that I was ambiguous. I meant "in this case", not in general. Of course, you're right. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2023-11-10 19:30 +0100 |
| Message-ID | <HyEqt-4vln-7@gated-at.bofh.it> |
| In reply to | #263340 |
tomas@tuxteam.de wrote: > On Fri, Nov 10, 2023 at 03:32:53PM +0000, fxkl47BF@protonmail.com wrote: > > On Fri, 10 Nov 2023, Vincent Lefevre wrote: > > > > > On 2023-11-10 10:57:21 +0100, Michael wrote: > > >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > > >>> No, this is not a normal phenomenon for bookworm upgrades. I've never > > >>> heard of it happening to anyone before. > > >> > > >> i disagree. i had the same problem b/c i also had dropbear installed. > > > > > > It would be interesting to know why dropbear got installed > > > > at sometime in the distance past i thought it would be handy > > my initial ramdisk is set up so i can remotely unlock the filesystems > > Wait a minute: dropbear is supposed to run in the initramfs, while > sshd will be active afterwards, after pivot-root and all that, right? > > Then I don't quite get why they should collide at all. Because dropbear *can* be run as an ordinary sshd, and some people do. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Vincent Lefevre <vincent@vinc17.net> |
|---|---|
| Date | 2023-11-13 11:20 +0100 |
| Message-ID | <HzCcV-55Y9-3@gated-at.bofh.it> |
| In reply to | #263336 |
On 2023-11-10 15:32:53 +0000, fxkl47BF@protonmail.com wrote: > On Fri, 10 Nov 2023, Vincent Lefevre wrote: > > > On 2023-11-10 10:57:21 +0100, Michael wrote: > >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote: > >>> No, this is not a normal phenomenon for bookworm upgrades. I've never > >>> heard of it happening to anyone before. > >> > >> i disagree. i had the same problem b/c i also had dropbear installed. > > > > It would be interesting to know why dropbear got installed > > at sometime in the distance past i thought it would be handy > my initial ramdisk is set up so i can remotely unlock the filesystems This is what I've done for my old laptop, but the dropbear package is *not* needed for that! You just need the dropbear-initramfs package (dropbear-bin will be installed as a consequence as a dependency, but not the dropbear package, which contains the startup scripts). If you install the dropbear package, i.e. the startup scripts, this means that you want dropbear as you're main sshd daemon rather than the one from OpenSSH. -- Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2023-11-13 11:20 +0100 |
| Message-ID | <HzCcW-55Y9-11@gated-at.bofh.it> |
| In reply to | #263462 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Nov 13, 2023 at 11:10:17AM +0100, Vincent Lefevre wrote: [...] > This is what I've done for my old laptop, but the dropbear package > is *not* needed for that! You just need the dropbear-initramfs > package [...] Aha -- now I know the full story. Thanks, Vincent (and all the other smart folks sharing their wisdom here) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2023-11-09 19:30 +0100 |
| Message-ID | <HyhWV-4hJw-1@gated-at.bofh.it> |
| In reply to | #263291 |
On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote:
>
> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
> > i upgraded from bullseye to bookworm with no problems
> > when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
> >
> > debug1: Requesting X11 forwarding with authentication spoofing.
> > debug1: Sending environment.
> > debug1: Sending env LANG = en_US.UTF-8
> > debug1: Sending env LC_ALL = en_US.UTF-8
> > X11 forwarding request failed on channel 0
> >
> > the .Xauthority file is not updated
> > is there new security or configuration
>
> On the server, run:
>
> grep X11 /etc/ssh/sshd_config
>
> That should tell you whether X11Forwarding and its related options have
> been disabled.
Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ :
$ sudo ls /etc/ssh/sshd_config.d/
10-pubkey_auth.conf 20-no_root_login.conf
And:
$ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf
PasswordAuthentication no
ChallengeResponseAuthentication no
KerberosAuthentication no
KerberosOrLocalPasswd no
GSSAPIAuthentication no
UsePAM no
PubkeyAuthentication yes
Jeff
[toc] | [prev] | [next] | [standalone]
| From | fxkl47BF@protonmail.com |
|---|---|
| Date | 2023-11-09 19:40 +0100 |
| Message-ID | <Hyi6B-4hN1-7@gated-at.bofh.it> |
| In reply to | #263298 |
On Thu, 9 Nov 2023, Jeffrey Walton wrote: > On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote: >> >> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote: >>> i upgraded from bullseye to bookworm with no problems >>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails >>> >>> debug1: Requesting X11 forwarding with authentication spoofing. >>> debug1: Sending environment. >>> debug1: Sending env LANG = en_US.UTF-8 >>> debug1: Sending env LC_ALL = en_US.UTF-8 >>> X11 forwarding request failed on channel 0 >>> >>> the .Xauthority file is not updated >>> is there new security or configuration >> >> On the server, run: >> >> grep X11 /etc/ssh/sshd_config >> >> That should tell you whether X11Forwarding and its related options have >> been disabled. > > Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ : > > $ sudo ls /etc/ssh/sshd_config.d/ > 10-pubkey_auth.conf 20-no_root_login.conf > > And: > > $ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf > PasswordAuthentication no > ChallengeResponseAuthentication no > KerberosAuthentication no > KerberosOrLocalPasswd no > GSSAPIAuthentication no > UsePAM no > PubkeyAuthentication yes > > Jeff > my /etc/ssh/sshd_config.d/ is empty
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2023-11-10 01:00 +0100 |
| Message-ID | <Hyn6h-4kFk-1@gated-at.bofh.it> |
| In reply to | #263299 |
On Thu, Nov 9, 2023 at 6:16 PM <fxkl47BF@protonmail.com> wrote: > > On Thu, 9 Nov 2023, Jeffrey Walton wrote: > > > On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote: > >> > >> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote: > >>> i upgraded from bullseye to bookworm with no problems > >>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails > >>> > >>> debug1: Requesting X11 forwarding with authentication spoofing. > >>> debug1: Sending environment. > >>> debug1: Sending env LANG = en_US.UTF-8 > >>> debug1: Sending env LC_ALL = en_US.UTF-8 > >>> X11 forwarding request failed on channel 0 > >>> > >>> the .Xauthority file is not updated > >>> is there new security or configuration > >> > >> On the server, run: > >> > >> grep X11 /etc/ssh/sshd_config > >> > >> That should tell you whether X11Forwarding and its related options have > >> been disabled. > > > > Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ : > > > > $ sudo ls /etc/ssh/sshd_config.d/ > > 10-pubkey_auth.conf 20-no_root_login.conf > > > > And: > > > > $ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf > > PasswordAuthentication no > > ChallengeResponseAuthentication no > > KerberosAuthentication no > > KerberosOrLocalPasswd no > > GSSAPIAuthentication no > > UsePAM no > > PubkeyAuthentication yes > > my /etc/ssh/sshd_config.d/ is empty /etc/ssh/sshd_config.d/ is where you are supposed to make changes. Otherwise, new config files get written during upgrades, and overwrite the old settings. Changes in sshd_config.d always survive, and always take precedence over the distro's settings. Jeff
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web