Dank Rene.

Als ik echter in /etc/ssh/ssh_config      IdentityFile ~/.ssh/id_rsa
meegeef
dan zie ik bij het connecten:

debug1: Offering RSA public key: /root/.ssh/id_rsa
Dit lijkt me onjuist.






Graag ontvang ik een bevestiging retour.

Met vriendelijke groet,

Bas Neve
[email protected]
316 14 12 00 71









Op wo 17 okt. 2018 om 10:26 schreef RenĂ© de Groot <[email protected]>:

> Hallo Bas,
>
> Volgens mij gaat het mis bij je keypair, je hebt je public key ipv private
> key als identity staan.
>
> Met vriendelijke groet,
>
> René de Groot
> ------------------------------
> *From:* Bas Neve <[email protected]>
> *Sent:* Wednesday, October 17, 2018 8:10 AM
> *To:* [email protected]
> *Subject:* RE: SSH
>
> Beste mensen,
>
> Excuses voor de vorige email.
>
> Als ik met Putty verbinding maak met een remote host dan gaat dit prima.
> Als ik echter met ssh op een debian machine probeer in te loggen op
> diezelde machine dan lukt dit niet. Er draait geen selinux en mijn client
> heb ik als volgt geconfigureerd.
>
> Host *
> #   ForwardAgent yes
> #   ForwardX11 no
> #   ForwardX11Trusted yes
> #   RhostsRSAAuthentication no
> #   RSAAuthentication yes
>     PasswordAuthentication no
> #   HostbasedAuthentication no
> #   GSSAPIAuthentication no
> #   GSSAPIDelegateCredentials no
> #   GSSAPIKeyExchange no
> #   GSSAPITrustDNS no
> #   BatchMode no
> #   CheckHostIP yes
> #   AddressFamily any
> #   ConnectTimeout 0
> #   StrictHostKeyChecking ask
> #   IdentityFile ~/.ssh/identity
>     IdentityFile ~/.ssh/id_rsa.pub
> #   IdentityFile ~/.ssh/id_dsa
> #   IdentityFile ~/.ssh/id_ecdsa
> #   IdentityFile ~/.ssh/id_ed25519
> #   Port 22
> #   Protocol 2
> #   Cipher 3des
> #   Ciphers
> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc
> #   MACs hmac-md5,hmac-sha1,[email protected],hmac-ripemd160
> #   EscapeChar ~
> #   Tunnel no
> #   TunnelDevice any:any
> #   PermitLocalCommand no
> #   VisualHostKey no
> #   ProxyCommand ssh -q -W %h:%p gateway.example.com
> #   RekeyLimit 1G 1h
>     SendEnv LANG LC_*
>     HashKnownHosts yes
> #   GSSAPIAuthentication yes
> IdentitiesOnly yes
> bas@debian:/etc/ssh$
>
> drwx------  2 bas bas 4096 Oct 16 11:51 .
> drwxr-x--- 18 bas bas 4096 Oct 16 10:44 ..
> -rw-r--r--  1 bas bas  405 Oct 16 11:51 authorized_keys
> -rw-------  1 bas bas 1486 Oct 12 07:48 id_rsa
> -rw-------  1 bas bas 1486 Oct 12 07:50 id_rsa.ppk
> -rw-r--r--  1 bas bas  405 Oct  7 07:12 id_rsa.pub
> -rw-r--r--  1 bas bas  884 Oct 15 18:35 known_hosts
> bas@debian:~/.ssh$
>
> ssh -vvv [email protected] -p 9999
> OpenSSH_7.4p1 Debian-10+deb9u4, OpenSSL 1.0.2l  25 May 2017
> debug1: Reading configuration data /etc/ssh/ssh_config
> debug1: /etc/ssh/ssh_config line 19: Applying options for *
> debug2: resolving "deserver.nl" port 9999
> debug2: ssh_connect_direct: needpriv 0
> debug1: Connecting to deserver.nl [100.100.100.100] port 9999.
> debug1: Connection established.
> debug1: identity file /home/bas/.ssh/id_rsa.pub type 1
> debug1: key_load_public: No such file or directory
> debug1: identity file /home/bas/.ssh/id_rsa.pub-cert type -1
> debug1: Enabling compatibility mode for protocol 2.0
> debug1: Local version string SSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u4
> debug1: Remote protocol version 2.0, remote software version OpenSSH_5.3
> debug1: match: OpenSSH_5.3 pat OpenSSH_5* compat 0x0c000000
> debug2: fd 3 setting O_NONBLOCK
> debug1: Authenticating to deserver.nl:9999 as 'user'
> debug3: put_host_port: [deserver.nl]:9999
> debug3: hostkeys_foreach: reading file "/home/bas/.ssh/known_hosts"
> debug3: record_hostkey: found key type RSA in file
> /home/bas/.ssh/known_hosts:1
> debug3: load_hostkeys: loaded 1 keys from [deserver.nl]:9999
> debug3: order_hostkeyalgs: prefer hostkeyalgs:
> [email protected],rsa-sha2-512,rsa-sha2-256,ssh-rsa
> debug3: send packet: type 20
> debug1: SSH2_MSG_KEXINIT sent
> debug3: receive packet: type 20
> debug1: SSH2_MSG_KEXINIT received
> debug2: local client KEXINIT proposal
> debug2: KEX algorithms: curve25519-sha256,[email protected]
> ,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-c
> debug2: host key algorithms: [email protected]
> ,rsa-sha2-512,rsa-sha2-256,ssh-rsa,
> [email protected],
> [email protected],
> [email protected],[email protected]
> ,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519
> debug2: ciphers ctos: [email protected]
> ,aes128-ctr,aes192-ctr,aes256-ctr,[email protected],
> [email protected],aes128-cbc,aes192-cbc,aes256-cbc
> debug2: ciphers stoc: [email protected]
> ,aes128-ctr,aes192-ctr,aes256-ctr,[email protected],
> [email protected],aes128-cbc,aes192-cbc,aes256-cbc
> debug2: MACs ctos: [email protected],[email protected],
> [email protected],[email protected],
> [email protected],[email protected],[email protected]
> ,hmac-sha2-256,hmac-sha2-512,hmac-sha1
> debug2: MACs stoc: [email protected],[email protected],
> [email protected],[email protected],
> [email protected],[email protected],[email protected]
> ,hmac-sha2-256,hmac-sha2-512,hmac-sha1
> debug2: compression ctos: none,[email protected],zlib
> debug2: compression stoc: none,[email protected],zlib
> debug2: languages ctos:
> debug2: languages stoc:
> debug2: first_kex_follows 0
> debug2: reserved 0
> debug2: peer server KEXINIT proposal
> debug2: KEX algorithms:
> diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
> debug2: host key algorithms: ssh-rsa,ssh-dss
> debug2: ciphers ctos:
> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,
> [email protected]
> debug2: ciphers stoc:
> aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,
> [email protected]
> debug2: MACs ctos: hmac-md5,hmac-sha1,[email protected]
> ,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,[email protected]
> ,hmac-sha1-96,hmac-md5-96
> debug2: MACs stoc: hmac-md5,hmac-sha1,[email protected]
> ,hmac-sha2-256,hmac-sha2-512,hmac-ripemd160,[email protected]
> ,hmac-sha1-96,hmac-md5-96
> debug2: compression ctos: none,[email protected]
> debug2: compression stoc: none,[email protected]
> debug2: languages ctos:
> debug2: languages stoc:
> debug2: first_kex_follows 0
> debug2: reserved 0
> debug1: kex: algorithm: diffie-hellman-group-exchange-sha256
> debug1: kex: host key algorithm: ssh-rsa
> debug1: kex: server->client cipher: aes128-ctr MAC: [email protected] 
> compression:
> none
> debug1: kex: client->server cipher: aes128-ctr MAC: [email protected] 
> compression:
> none
> debug3: send packet: type 34
> debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(2048<3072<8192) sent
> debug3: receive packet: type 31
> debug1: got SSH2_MSG_KEX_DH_GEX_GROUP
> debug2: bits set: 1529/3072
> debug3: send packet: type 32
> debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
> debug3: receive packet: type 33
> debug1: got SSH2_MSG_KEX_DH_GEX_REPLY
> debug1: Server host key: ssh-rsa
> SHA256:dGgUvUrEOwWirFhGN7GTJ0HnHyalIqzipdM3gfjRBzg
> debug3: put_host_port: [100.100.100.100]:9999
> debug3: put_host_port: [deserver.nl]:9999
> debug3: hostkeys_foreach: reading file "/home/bas/.ssh/known_hosts"
> debug3: record_hostkey: found key type RSA in file
> /home/bas/.ssh/known_hosts:1
> debug3: load_hostkeys: loaded 1 keys from [desever.nl]:9999
> debug3: hostkeys_foreach: reading file "/home/bas/.ssh/known_hosts"
> debug3: record_hostkey: found key type RSA in file
> /home/bas/.ssh/known_hosts:2
> debug3: load_hostkeys: loaded 1 keys from [100.100.100.100]:9999
> debug1: Host '[deserver.nl]:9999' is known and matches the RSA host key.
> debug1: Found key in /home/bas/.ssh/known_hosts:1
> debug2: bits set: 1575/3072
> debug3: send packet: type 21
> debug2: set_newkeys: mode 1
> debug1: rekey after 4294967296 blocks
> debug1: SSH2_MSG_NEWKEYS sent
> debug1: expecting SSH2_MSG_NEWKEYS
> debug3: receive packet: type 21
> debug1: SSH2_MSG_NEWKEYS received
> debug2: set_newkeys: mode 0
> debug1: rekey after 4294967296 blocks
> debug2: key: /home/bas/.ssh/id_rsa.pub (0x5631bfe8da80), agent
> debug3: send packet: type 5
> debug3: receive packet: type 6
> debug2: service_accept: ssh-userauth
> debug1: SSH2_MSG_SERVICE_ACCEPT received
> debug3: send packet: type 50
> debug3: receive packet: type 51
> debug1: Authentications that can continue:
> publickey,gssapi-keyex,gssapi-with-mic,password
> debug3: start over, passed a different list
> publickey,gssapi-keyex,gssapi-with-mic,password
> debug3: preferred publickey,keyboard-interactive
> debug3: authmethod_lookup publickey
> debug3: remaining preferred: keyboard-interactive
> debug3: authmethod_is_enabled publickey
> debug1: Next authentication method: publickey
> debug1: Offering RSA public key: /home/bas/.ssh/id_rsa.pub
> debug3: send_pubkey_test
> debug3: send packet: type 50
> debug2: we sent a publickey packet, wait for reply
> debug3: receive packet: type 51
> debug1: Authentications that can continue:
> publickey,gssapi-keyex,gssapi-with-mic,password
> debug2: we did not send a packet, disable method
> debug1: No more authentication methods to try.
> Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).
> bas@debian:~$
>
> Iemand een id ?
> Graag ontvang ik een bevestiging retour.
>
> Met vriendelijke groet,
>
> Bas Neve
> [email protected]
> 316 14 12 00 71
>
>
>
>
>
>
>
>
>
>

Antwoord per e-mail aan