Steph,

Thanks.  That did it!  I thought I had tried the no passphrase option during
one of my sessions, but I guess I hadn't.  Thanks a lot!

Rob.

 -----Original Message-----
From:   [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]  On Behalf Of
Stephanie Thomas
Sent:   Wednesday, May 16, 2001 5:57 PM
To:     Robert Forkner
Cc:     [EMAIL PROTECTED]
Subject:        Re: FATAL error after using ssh-keygen2

Hi Robert,

You'll need to generate the hostkeys without a passphrase:

As root:

# /usr/local/bin/ssh-keygen2 -b 1024 -P /etc/ssh2/hostkey

Hostkeys must not have a passphrase.

Best Regards,

Steph

Robert Forkner wrote:
>
> I'm running SSH 2.3 on an AIX 4.3.3 box.  I want to change my private and
> public keys, but when after I run the following command:
>
> /usr/local/bin/ssh-keygen2 -b 1024 /etc/ssh2/hostkey
>
> ...I can't restart SSH.  When I try to, I get the following error:
>
> FATAL ERROR: ssh_privkey_read from /etc/ssh2/hostkey failed.
>
> I looked in /etc/ssh2/sshd2_config file and the HostKeyFIle and
> PublicHostKeyFile are configured as follows:
>
>         HostKeyFile                            hostkey
>         PublicHostKeyFile          hostkey.pub
>
> I tried putting a fully qualified path here as well and that didn't change
> anything.
>
> I used a backup to fix it - just so I could break it again - and when I
> deleted a public key from the /.ssh2/knownhosts directory, the same error
> occurred.  What am I missing here, because I would really like to change
> this key.
>
> Rob.
>
>   ------------------------------------------------------------------------
----------------------------
>                   Name: winmail.dat
>    winmail.dat    Type: application/ms-tnef
>               Encoding: base64

--
*********************************
Please note that for support cases,
if I have not heard otherwise within five
business days, I will assume that your issue
is resolved.

Stephanie Thomas
Technical Support Specialist
SSH Secure Shell
GIAC Certified
Unix Security Administrator
SSH Communications Security Inc.
http://www.ssh.com/support/ssh
*********************************

Reply via email to