Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #263285 > unrolled thread

upgrade to bookworm broke ssh x11 forwarding

Started byfxkl47BF@protonmail.com
First post2023-11-09 16:10 +0100
Last post2023-11-10 01:00 +0100
Articles 18 — 9 participants

Back to article view | Back to linux.debian.user


Contents

  upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 16:10 +0100
    Re: upgrade to bookworm broke ssh x11 forwarding Greg Wooledge <greg@wooledge.org> - 2023-11-09 17:50 +0100
      Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 17:50 +0100
        Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 18:10 +0100
          Re: upgrade to bookworm broke ssh x11 forwarding Greg Wooledge <greg@wooledge.org> - 2023-11-09 19:10 +0100
            Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 19:40 +0100
            Re: upgrade to bookworm broke ssh x11 forwarding Michael <ml@hemathor.de> - 2023-11-10 11:10 +0100
              Re: upgrade to bookworm broke ssh x11 forwarding Vincent Lefevre <vincent@vinc17.net> - 2023-11-10 15:50 +0100
                Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-10 16:40 +0100
                  Re: upgrade to bookworm broke ssh x11 forwarding David Wright <deblis@lionunicorn.co.uk> - 2023-11-10 17:20 +0100
                  Re: upgrade to bookworm broke ssh x11 forwarding <tomas@tuxteam.de> - 2023-11-10 18:50 +0100
                    Re: upgrade to bookworm broke ssh x11 forwarding tomas@tuxteam.de - 2023-11-10 19:30 +0100
                    Re: upgrade to bookworm broke ssh x11 forwarding Dan Ritter <dsr@randomstring.org> - 2023-11-10 19:30 +0100
                  Re: upgrade to bookworm broke ssh x11 forwarding Vincent Lefevre <vincent@vinc17.net> - 2023-11-13 11:20 +0100
                    Re: upgrade to bookworm broke ssh x11 forwarding <tomas@tuxteam.de> - 2023-11-13 11:20 +0100
      Re: upgrade to bookworm broke ssh x11 forwarding Jeffrey Walton <noloader@gmail.com> - 2023-11-09 19:30 +0100
        Re: upgrade to bookworm broke ssh x11 forwarding fxkl47BF@protonmail.com - 2023-11-09 19:40 +0100
          Re: upgrade to bookworm broke ssh x11 forwarding Jeffrey Walton <noloader@gmail.com> - 2023-11-10 01:00 +0100

#263285 — upgrade to bookworm broke ssh x11 forwarding

Fromfxkl47BF@protonmail.com
Date2023-11-09 16:10 +0100
Subjectupgrade to bookworm broke ssh x11 forwarding
Message-ID<HyePn-4fZl-1@gated-at.bofh.it>
i upgraded from bullseye to bookworm with no problems
when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails

debug1: Requesting X11 forwarding with authentication spoofing.
debug1: Sending environment.
debug1: Sending env LANG = en_US.UTF-8
debug1: Sending env LC_ALL = en_US.UTF-8
X11 forwarding request failed on channel 0

the .Xauthority file is not updated
is there new security or configuration

[toc] | [next] | [standalone]


#263291

FromGreg Wooledge <greg@wooledge.org>
Date2023-11-09 17:50 +0100
Message-ID<Hygo9-4gJ5-3@gated-at.bofh.it>
In reply to#263285
On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
> i upgraded from bullseye to bookworm with no problems
> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
> 
> debug1: Requesting X11 forwarding with authentication spoofing.
> debug1: Sending environment.
> debug1: Sending env LANG = en_US.UTF-8
> debug1: Sending env LC_ALL = en_US.UTF-8
> X11 forwarding request failed on channel 0
> 
> the .Xauthority file is not updated
> is there new security or configuration

On the server, run:

    grep X11 /etc/ssh/sshd_config

That should tell you whether X11Forwarding and its related options have
been disabled.

[toc] | [prev] | [next] | [standalone]


#263292

Fromfxkl47BF@protonmail.com
Date2023-11-09 17:50 +0100
Message-ID<Hygo9-4gJ5-9@gated-at.bofh.it>
In reply to#263291
On Thu, 9 Nov 2023, Greg Wooledge wrote:

> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
>> i upgraded from bullseye to bookworm with no problems
>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
>>
>> debug1: Requesting X11 forwarding with authentication spoofing.
>> debug1: Sending environment.
>> debug1: Sending env LANG = en_US.UTF-8
>> debug1: Sending env LC_ALL = en_US.UTF-8
>> X11 forwarding request failed on channel 0
>>
>> the .Xauthority file is not updated
>> is there new security or configuration
>
> On the server, run:
>
>    grep X11 /etc/ssh/sshd_config
>
> That should tell you whether X11Forwarding and its related options have
> been disabled.
>

$ grep X11 /etc/ssh/sshd_config
X11Forwarding yes

[toc] | [prev] | [next] | [standalone]


#263294

Fromfxkl47BF@protonmail.com
Date2023-11-09 18:10 +0100
Message-ID<HygHv-4h4N-3@gated-at.bofh.it>
In reply to#263292
On Thu, 9 Nov 2023, fxkl47BF@protonmail.com wrote:

> On Thu, 9 Nov 2023, Greg Wooledge wrote:
>
>> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
>>> i upgraded from bullseye to bookworm with no problems
>>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
>>>
>>> debug1: Requesting X11 forwarding with authentication spoofing.
>>> debug1: Sending environment.
>>> debug1: Sending env LANG = en_US.UTF-8
>>> debug1: Sending env LC_ALL = en_US.UTF-8
>>> X11 forwarding request failed on channel 0
>>>
>>> the .Xauthority file is not updated
>>> is there new security or configuration
>>
>> On the server, run:
>>
>>    grep X11 /etc/ssh/sshd_config
>>
>> That should tell you whether X11Forwarding and its related options have
>> been disabled.
>>
>
> $ grep X11 /etc/ssh/sshd_config
> X11Forwarding yes
>
>

now it makes a bit more sense
sshd isn't running
for some reason the upgrade switched to dropbear
is this a new thing for bookworm
is there a reason i shouldn't disable dropbear and use sshd

[toc] | [prev] | [next] | [standalone]


#263296

FromGreg Wooledge <greg@wooledge.org>
Date2023-11-09 19:10 +0100
Message-ID<HyhDA-4hCV-5@gated-at.bofh.it>
In reply to#263294
On Thu, Nov 09, 2023 at 04:59:32PM +0000, fxkl47BF@protonmail.com wrote:
> now it makes a bit more sense
> sshd isn't running
> for some reason the upgrade switched to dropbear
> is this a new thing for bookworm
> is there a reason i shouldn't disable dropbear and use sshd

No, this is not a normal phenomenon for bookworm upgrades.  I've never
heard of it happening to anyone before.

You should be able to reinstall openssh-server and remove dropbear
and get back to normal, unless there's something else unusual in
your package set.  As this situation is (AFAIK) unique to your system,
you'll have to be the one to try it and see what happens.

[toc] | [prev] | [next] | [standalone]


#263300

Fromfxkl47BF@protonmail.com
Date2023-11-09 19:40 +0100
Message-ID<Hyi6B-4hN1-3@gated-at.bofh.it>
In reply to#263296
On Thu, 9 Nov 2023, Greg Wooledge wrote:

> On Thu, Nov 09, 2023 at 04:59:32PM +0000, fxkl47BF@protonmail.com wrote:
>> now it makes a bit more sense
>> sshd isn't running
>> for some reason the upgrade switched to dropbear
>> is this a new thing for bookworm
>> is there a reason i shouldn't disable dropbear and use sshd
>
> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> heard of it happening to anyone before.
>
> You should be able to reinstall openssh-server and remove dropbear
> and get back to normal, unless there's something else unusual in
> your package set.  As this situation is (AFAIK) unique to your system,
> you'll have to be the one to try it and see what happens.
>

openssh was installed just not running
i stopped and disabled dropbear and started sshd
all is right for now
thanks

[toc] | [prev] | [next] | [standalone]


#263327

FromMichael <ml@hemathor.de>
Date2023-11-10 11:10 +0100
Message-ID<HywCB-4qPH-5@gated-at.bofh.it>
In reply to#263296
On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> heard of it happening to anyone before.


i disagree. i had the same problem b/c i also had dropbear installed. for 
some reason the dropbear daemon is started first in bookworm, so port 22 
was already in use when sshd was started. reading the log file (aka 
systemd-journal) was very enlightening.

a simple 

  systemctl stop dropbear.service
  systemctl disable dropbear.service
  systemctl start ssh.service

was enough to solve the problem. of course, one needs access to the 
console...

greetings...

[toc] | [prev] | [next] | [standalone]


#263335

FromVincent Lefevre <vincent@vinc17.net>
Date2023-11-10 15:50 +0100
Message-ID<HyAZz-4teJ-5@gated-at.bofh.it>
In reply to#263327
On 2023-11-10 10:57:21 +0100, Michael wrote:
> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> > No, this is not a normal phenomenon for bookworm upgrades.  I've never
> > heard of it happening to anyone before.
> 
> i disagree. i had the same problem b/c i also had dropbear installed.

It would be interesting to know why dropbear got installed (if
openssh-server was already installed, this is rather surprising),
e.g. with "aptitude why dropbear".

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


#263336

Fromfxkl47BF@protonmail.com
Date2023-11-10 16:40 +0100
Message-ID<HyBLX-4tJT-1@gated-at.bofh.it>
In reply to#263335
On Fri, 10 Nov 2023, Vincent Lefevre wrote:

> On 2023-11-10 10:57:21 +0100, Michael wrote:
>> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
>>> No, this is not a normal phenomenon for bookworm upgrades.  I've never
>>> heard of it happening to anyone before.
>>
>> i disagree. i had the same problem b/c i also had dropbear installed.
>
> It would be interesting to know why dropbear got installed

at sometime in the distance past i thought it would be handy
my initial ramdisk is set up so i can remotely unlock the filesystems

[toc] | [prev] | [next] | [standalone]


#263337

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2023-11-10 17:20 +0100
Message-ID<HyCoF-4uck-1@gated-at.bofh.it>
In reply to#263336
On Fri 10 Nov 2023 at 15:32:53 (+0000), fxkl47BF@protonmail.com wrote:
> On Fri, 10 Nov 2023, Vincent Lefevre wrote:
> 
> > On 2023-11-10 10:57:21 +0100, Michael wrote:
> >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> >>> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> >>> heard of it happening to anyone before.
> >>
> >> i disagree. i had the same problem b/c i also had dropbear installed.
> >
> > It would be interesting to know why dropbear got installed
> 
> at sometime in the distance past i thought it would be handy
> my initial ramdisk is set up so i can remotely unlock the filesystems

You may have been relying on a race condition as to whether
openssh or dropbear started first, and were just lucky in bullseye.

The OP's "for some reason the upgrade switched to dropbear" is
somewhat ambiguous, but it looks like the same problem. Perhaps
Greg interpreted that "switched to" as meaning "installed as
a dependency".

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#263340

From<tomas@tuxteam.de>
Date2023-11-10 18:50 +0100
Message-ID<HyDNL-4uTF-1@gated-at.bofh.it>
In reply to#263336

[Multipart message — attachments visible in raw view] — view raw

On Fri, Nov 10, 2023 at 03:32:53PM +0000, fxkl47BF@protonmail.com wrote:
> On Fri, 10 Nov 2023, Vincent Lefevre wrote:
> 
> > On 2023-11-10 10:57:21 +0100, Michael wrote:
> >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> >>> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> >>> heard of it happening to anyone before.
> >>
> >> i disagree. i had the same problem b/c i also had dropbear installed.
> >
> > It would be interesting to know why dropbear got installed
> 
> at sometime in the distance past i thought it would be handy
> my initial ramdisk is set up so i can remotely unlock the filesystems

Wait a minute: dropbear is supposed to run in the initramfs, while
sshd will be active afterwards, after pivot-root and all that, right?

Then I don't quite get why they should collide at all.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#263341

Fromtomas@tuxteam.de
Date2023-11-10 19:30 +0100
Message-ID<HyEqt-4vln-5@gated-at.bofh.it>
In reply to#263340

[Multipart message — attachments visible in raw view] — view raw

On Fri, Nov 10, 2023 at 01:01:28PM -0500, Dan Ritter wrote:
> tomas@tuxteam.de wrote: 

[...]

> > Wait a minute: dropbear is supposed to run in the initramfs, while
> > sshd will be active afterwards, after pivot-root and all that, right?
> > 
> > Then I don't quite get why they should collide at all.
> 
> Because dropbear *can* be run as an ordinary sshd, and some
> people do.

Ugh. Re-reading I realise that I was ambiguous. I meant
"in this case", not in general. Of course, you're right.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#263342

FromDan Ritter <dsr@randomstring.org>
Date2023-11-10 19:30 +0100
Message-ID<HyEqt-4vln-7@gated-at.bofh.it>
In reply to#263340
tomas@tuxteam.de wrote: 
> On Fri, Nov 10, 2023 at 03:32:53PM +0000, fxkl47BF@protonmail.com wrote:
> > On Fri, 10 Nov 2023, Vincent Lefevre wrote:
> > 
> > > On 2023-11-10 10:57:21 +0100, Michael wrote:
> > >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> > >>> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> > >>> heard of it happening to anyone before.
> > >>
> > >> i disagree. i had the same problem b/c i also had dropbear installed.
> > >
> > > It would be interesting to know why dropbear got installed
> > 
> > at sometime in the distance past i thought it would be handy
> > my initial ramdisk is set up so i can remotely unlock the filesystems
> 
> Wait a minute: dropbear is supposed to run in the initramfs, while
> sshd will be active afterwards, after pivot-root and all that, right?
> 
> Then I don't quite get why they should collide at all.

Because dropbear *can* be run as an ordinary sshd, and some
people do.

-dsr-

[toc] | [prev] | [next] | [standalone]


#263462

FromVincent Lefevre <vincent@vinc17.net>
Date2023-11-13 11:20 +0100
Message-ID<HzCcV-55Y9-3@gated-at.bofh.it>
In reply to#263336
On 2023-11-10 15:32:53 +0000, fxkl47BF@protonmail.com wrote:
> On Fri, 10 Nov 2023, Vincent Lefevre wrote:
> 
> > On 2023-11-10 10:57:21 +0100, Michael wrote:
> >> On Thursday, 9 November 2023 19:08:25 CET, Greg Wooledge wrote:
> >>> No, this is not a normal phenomenon for bookworm upgrades.  I've never
> >>> heard of it happening to anyone before.
> >>
> >> i disagree. i had the same problem b/c i also had dropbear installed.
> >
> > It would be interesting to know why dropbear got installed
> 
> at sometime in the distance past i thought it would be handy
> my initial ramdisk is set up so i can remotely unlock the filesystems

This is what I've done for my old laptop, but the dropbear package
is *not* needed for that! You just need the dropbear-initramfs
package (dropbear-bin will be installed as a consequence as a
dependency, but not the dropbear package, which contains the
startup scripts). If you install the dropbear package, i.e. the
startup scripts, this means that you want dropbear as you're
main sshd daemon rather than the one from OpenSSH.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [next] | [standalone]


#263463

From<tomas@tuxteam.de>
Date2023-11-13 11:20 +0100
Message-ID<HzCcW-55Y9-11@gated-at.bofh.it>
In reply to#263462

[Multipart message — attachments visible in raw view] — view raw

On Mon, Nov 13, 2023 at 11:10:17AM +0100, Vincent Lefevre wrote:

[...]

> This is what I've done for my old laptop, but the dropbear package
> is *not* needed for that! You just need the dropbear-initramfs
> package [...]

Aha -- now I know the full story. Thanks, Vincent (and all the other
smart folks sharing their wisdom here)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#263298

FromJeffrey Walton <noloader@gmail.com>
Date2023-11-09 19:30 +0100
Message-ID<HyhWV-4hJw-1@gated-at.bofh.it>
In reply to#263291
On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote:
>
> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
> > i upgraded from bullseye to bookworm with no problems
> > when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
> >
> > debug1: Requesting X11 forwarding with authentication spoofing.
> > debug1: Sending environment.
> > debug1: Sending env LANG = en_US.UTF-8
> > debug1: Sending env LC_ALL = en_US.UTF-8
> > X11 forwarding request failed on channel 0
> >
> > the .Xauthority file is not updated
> > is there new security or configuration
>
> On the server, run:
>
>     grep X11 /etc/ssh/sshd_config
>
> That should tell you whether X11Forwarding and its related options have
> been disabled.

Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ :

   $ sudo ls /etc/ssh/sshd_config.d/
   10-pubkey_auth.conf  20-no_root_login.conf

And:

    $ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf
    PasswordAuthentication no
    ChallengeResponseAuthentication no
    KerberosAuthentication no
    KerberosOrLocalPasswd no
    GSSAPIAuthentication no
    UsePAM no
    PubkeyAuthentication yes

Jeff

[toc] | [prev] | [next] | [standalone]


#263299

Fromfxkl47BF@protonmail.com
Date2023-11-09 19:40 +0100
Message-ID<Hyi6B-4hN1-7@gated-at.bofh.it>
In reply to#263298
On Thu, 9 Nov 2023, Jeffrey Walton wrote:

> On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote:
>>
>> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
>>> i upgraded from bullseye to bookworm with no problems
>>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
>>>
>>> debug1: Requesting X11 forwarding with authentication spoofing.
>>> debug1: Sending environment.
>>> debug1: Sending env LANG = en_US.UTF-8
>>> debug1: Sending env LC_ALL = en_US.UTF-8
>>> X11 forwarding request failed on channel 0
>>>
>>> the .Xauthority file is not updated
>>> is there new security or configuration
>>
>> On the server, run:
>>
>>     grep X11 /etc/ssh/sshd_config
>>
>> That should tell you whether X11Forwarding and its related options have
>> been disabled.
>
> Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ :
>
>   $ sudo ls /etc/ssh/sshd_config.d/
>   10-pubkey_auth.conf  20-no_root_login.conf
>
> And:
>
>    $ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf
>    PasswordAuthentication no
>    ChallengeResponseAuthentication no
>    KerberosAuthentication no
>    KerberosOrLocalPasswd no
>    GSSAPIAuthentication no
>    UsePAM no
>    PubkeyAuthentication yes
>
> Jeff
>

my /etc/ssh/sshd_config.d/ is empty

[toc] | [prev] | [next] | [standalone]


#263310

FromJeffrey Walton <noloader@gmail.com>
Date2023-11-10 01:00 +0100
Message-ID<Hyn6h-4kFk-1@gated-at.bofh.it>
In reply to#263299
On Thu, Nov 9, 2023 at 6:16 PM <fxkl47BF@protonmail.com> wrote:
>
> On Thu, 9 Nov 2023, Jeffrey Walton wrote:
>
> > On Thu, Nov 9, 2023 at 11:43 AM Greg Wooledge <greg@wooledge.org> wrote:
> >>
> >> On Thu, Nov 09, 2023 at 03:01:29PM +0000, fxkl47BF@protonmail.com wrote:
> >>> i upgraded from bullseye to bookworm with no problems
> >>> when i try ssh with -X/-Y to the bookworm machine x11 forwarding fails
> >>>
> >>> debug1: Requesting X11 forwarding with authentication spoofing.
> >>> debug1: Sending environment.
> >>> debug1: Sending env LANG = en_US.UTF-8
> >>> debug1: Sending env LC_ALL = en_US.UTF-8
> >>> X11 forwarding request failed on channel 0
> >>>
> >>> the .Xauthority file is not updated
> >>> is there new security or configuration
> >>
> >> On the server, run:
> >>
> >>     grep X11 /etc/ssh/sshd_config
> >>
> >> That should tell you whether X11Forwarding and its related options have
> >> been disabled.
> >
> > Probably need a 'grep -IR' since overrides can be provided in sshd_config.d/ :
> >
> >   $ sudo ls /etc/ssh/sshd_config.d/
> >   10-pubkey_auth.conf  20-no_root_login.conf
> >
> > And:
> >
> >    $ sudo cat /etc/ssh/sshd_config.d/10-pubkey_auth.conf
> >    PasswordAuthentication no
> >    ChallengeResponseAuthentication no
> >    KerberosAuthentication no
> >    KerberosOrLocalPasswd no
> >    GSSAPIAuthentication no
> >    UsePAM no
> >    PubkeyAuthentication yes
>
> my /etc/ssh/sshd_config.d/ is empty

/etc/ssh/sshd_config.d/ is where you are supposed to make changes.
Otherwise, new config files get written during upgrades, and overwrite
the old settings. Changes in sshd_config.d always survive, and always
take precedence over the distro's settings.

Jeff

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web