Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1103391: incorrect signature when ssh'ing to an AIX server (Big End

    From jfp@21:1/5 to All on Thu Apr 17 04:50:01 2025
    XPost: linux.debian.ports.powerpc

    Package: openssh-client
    Version: 1:10.0p1-2
    Severity: important
    Tags: upstream
    X-Debbugs-Cc: debian-amd64@lists.debian.org, debian-powerpc@lists.debian.org User: debian-amd64@lists.debian.org
    Usertags: amd64
    User: debian-powerpc@lists.debian.org
    Usertags: ppc64el




    -- System Information:
    Debian Release: trixie/sid
    APT prefers unstable-debug
    APT policy: (500, 'unstable-debug'), (500, 'unstable')
    Architecture: amd64 (x86_64)

    Kernel: Linux 6.12.13-amd64 (SMP w/4 CPU threads; PREEMPT)
    Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
    Locale: LANG=en_NZ.UTF-8, LC_CTYPE=en_NZ.UTF-8 (charmap=UTF-8), LANGUAGE=en_NZ:en
    Shell: /bin/sh linked to /usr/bin/dash
    Init: systemd (via /run/systemd/system)

    Versions of packages openssh-client depends on:
    ii adduser 3.150
    ii init-system-helpers 1.68
    ii libc6 2.41-7
    ii libedit2 3.1-20250104-1
    ii libfido2-1 1.15.0-1+b1
    ii libgssapi-krb5-2 1.21.3-5
    ii libselinux1 3.8.1-1
    ii libssl3t64 3.5.0-1
    ii passwd 1:4.17.4-1
    ii zlib1g 1:1.3.dfsg+really1.3.1-1+b1

    Versions of packages openssh-client recommends:
    ii xauth 1:1.1.2-1.1

    Versions of packages openssh-client suggests:
    pn keychain <none>
    pn libpam-ssh <none>
    pn monkeysphere <none>
    ii ssh-askpass 1:1.2.4.1-16+b1

    -- no debconf information



    If I delete the key from the known_hosts I get the additional line just before the incorrect signature:
    debug2: ssh_ed25519_verify: crypto_sign_ed25519_open failed: -1


    debug1: OpenSSH_10.0p2 Debian-2, OpenSSL 3.5.0 8 Apr 2025
    debug3: Running on Linux 6.12.13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.13-1 (2025-02-09) x86_64
    debug3: Started with: ssh -vvvvvvvvvv SERVERNAME
    debug1: Reading configuration data /home/jfp/.ssh/config
    debug3: kex names ok: [diffie-hellman-group1-sha1]
    debug1: Reading configuration data /etc/ssh/ssh_config
    debug3: /etc/ssh/ssh_config line 19: Including file /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf depth 0
    debug1: Reading configuration data /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf
    debug3: /etc/ssh/ssh_config line 19: Including file /etc/ssh/ssh_config.d/ssh-jfp.conf depth 0
    debug1: Reading configuration data /etc/ssh/ssh_config.d/ssh-jfp.conf
    debug1: /etc/ssh/ssh_config line 21: Applying options for *
    debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/jfp/.ssh/known_hosts'
    debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/jfp/.ssh/known_hosts2'
    debug2: resolving "SERVERNAME" port 22
    debug3: resolve_host: lookup SERVERNAME:22
    debug3: channel_clear_timeouts: clearing
    debug3: ssh_connect_direct: entering
    debug1: Connecting to SERVERNAME [10.160.21.22] port 22.
    debug3: set_sock_tos: set socket 3 IP_TOS 0x10
    debug1: Connection established.
    debug1: identity file /home/jfp/.ssh/id_rsa type 0
    debug1: identity file /home/jfp/.ssh/id_rsa-cert type -1
    debug1: identity file /home/jfp/.ssh/id_ecdsa type -1
    debug1: identity file /home/jfp/.ssh/id_ecdsa-cert type -1
    debug1: identity file /home/jfp/.ssh/id_ecdsa_sk type -1
    debug1: identity file /home/jfp/.ssh/id_ecdsa_sk-cert type -1
    debug1: identity file /home/jfp/.ssh/id_ed25519 type 3
    debug1: identity file /home/jfp/.ssh/id_ed25519-cert type -1
    debug1: identity file /home/jfp/.ssh/id_ed25519_sk type -1
    debug1: identity file /home/jfp/.ssh/id_ed25519_sk-cert type -1
    debug1: identity file /home/jfp/.ssh/id_xmss type -1
    debug1: identity file /home/jfp/.ssh/id_xmss-cert type -1
    debug1: Local version string SSH-2.0-OpenSSH_10.0p2 Debian-2
    debug1: Remote protocol version 2.0, remote software version OpenSSH_9.9 debug1: compat_banner: match: OpenSSH_9.9 pat OpenSSH* compat 0x04000000 debug2: fd 3 setting O_NONBLOCK
    debug1: Authenticating to SERVERNAME:22 as 'jpi4319'
    debug3: record_hostkey: found key type ECDSA in file /home/jfp/.ssh/known_hosts:54
    debug3: load_hostkeys_file: loaded 1 keys from SERVERNAME
    debug3: order_hostkeyalgs: prefer hostkeyalgs: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp256
    debug3: send packet: type 20
    debug1: SSH2_MSG_KEXINIT sent
    debug3: receive packet: type 20
    debug1: SSH2_MSG_KEXINIT received
    debug2: local client KEXINIT proposal
    debug2: KEX algorithms: mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-
    hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
    debug2: host key algorithms: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp256,ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-
    nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256
    debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
    debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
    debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
    debug2: compression ctos: none,zlib@openssh.com
    debug2: compression stoc: none,zlib@openssh.com
    debug2: languages ctos:
    debug2: languages stoc:
    debug2: first_kex_follows 0
    debug2: reserved 0
    debug2: peer server KEXINIT proposal
    debug2: KEX algorithms: sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,mlkem768x25519-sha256,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-
    hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-s,kex-strict-s-v00@openssh.com
    debug2: host key algorithms: rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519
    debug2: ciphers ctos: aes128-ctr,aes192-ctr,aes256-ctr,chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com
    debug2: ciphers stoc: aes128-ctr,aes192-ctr,aes256-ctr,chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com
    debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
    debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
    debug2: compression ctos: none,zlib@openssh.com
    debug2: compression stoc: none,zlib@openssh.com
    debug2: languages ctos:
    debug2: languages stoc:
    debug2: first_kex_follows 0
    debug2: reserved 0
    debug3: kex_choose_conf: will use strict KEX ordering
    debug1: kex: algorithm: mlkem768x25519-sha256
    debug1: kex: host key algorithm: ecdsa-sha2-nistp256
    debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
    debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
    debug3: send packet: type 30
    debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
    debug3: receive packet: type 31
    debug1: SSH2_MSG_KEX_ECDH_REPLY received
    debug1: Server host key: ecdsa-sha2-nistp256 SHA256:v3CpWA7KYkA/0T/Zz2ogEoDFcng+0zhA7o52ASgQgiQ
    debug3: record_hostkey: found key type ECDSA in file /home/jfp/.ssh/known_hosts:54
    debug3: load_hostkeys_file: loaded 1 keys from SERVERNAME
    debug1: load_hostkeys: fopen /home/jfp/.ssh/known_hosts2: No such file or directory
    debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
    debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
    debug1: Host 'SERVERNAME' is known and matches the ECDSA host key.
    debug1: Found key in /home/jfp/.ssh/known_hosts:54
    ssh_dispatch_run_fatal: Connection to XX.XX.XX.XX port 22: incorrect signature

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 480
    Nodes: 16 (2 / 14)
    Uptime: 253:15:54
    Calls: 9,532
    Files: 13,650
    Messages: 6,138,097

© >>> Magnum BBS <<<, 2025