* OpenSSH: SSHD daemon (as SYSTEM) is partially broken @ 2020-02-27 18:09 n0nc3 2020-02-27 19:34 ` Bill Stewart 0 siblings, 1 reply; 4+ messages in thread From: n0nc3 @ 2020-02-27 18:09 UTC (permalink / raw) To: cygwin It appears Cygwin SSHD's functionality is partially broke in the later versions, where SSHD runs as SYSTEM (no longer cyg_server). On reboot, any attempt to SSH into the server *before* any previous logon attempt (RDP/locally/etc) is quickly denied: debug1: Offering public key: /home/<user>/.ssh/id_rsa debug3: send_pubkey_test debug2: we sent a publickey packet, wait for reply Connection closed by <server_addr> Once an RDP/local login is attempted, regardless of success/failure, subsequent ssh attempts will progress to the password prompt which eventually gets us in. The Event Viewer shows the attached error message, relating to a NULL SID and 0xC00000BB status. ssh_as_first_login.txt <http://cygwin.1069669.n5.nabble.com/file/t11987/ssh_as_first_login.txt> It was a rather vanilla 'ssh-host-config' run to get it installed: strict modes = no, no special ssh_/sshd_config settings at this point. Running latest cygwin packages on Windows Server 2016 Standard: CYGWIN_NT-10.0 <server_name> 3.1.4(0.340/5/3) 2020-02-19 08:49 x86_64 Cygwin ... openssh 8.2p1-1 OK -- Sent from: http://cygwin.1069669.n5.nabble.com/Cygwin-list-f3.html -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: OpenSSH: SSHD daemon (as SYSTEM) is partially broken 2020-02-27 18:09 OpenSSH: SSHD daemon (as SYSTEM) is partially broken n0nc3 @ 2020-02-27 19:34 ` Bill Stewart 2020-02-27 23:10 ` TestUser1 0 siblings, 1 reply; 4+ messages in thread From: Bill Stewart @ 2020-02-27 19:34 UTC (permalink / raw) To: cygwin On Thu, Feb 27, 2020 at 11:09 AM n0nc3 <pkoshar@compunetix.com> wrote: It appears Cygwin SSHD's functionality is partially broke in the later > versions, where SSHD runs as SYSTEM (no longer cyg_server). > > On reboot, any attempt to SSH into the server *before* any previous logon > attempt (RDP/locally/etc) is quickly denied: > > debug1: Offering public key: /home/<user>/.ssh/id_rsa > debug3: send_pubkey_test > debug2: we sent a publickey packet, wait for reply > Connection closed by <server_addr> > > Once an RDP/local login is attempted, regardless of success/failure, > subsequent ssh attempts will progress to the password prompt which > eventually gets us in. > This is a known issue on OS versions older than 8.1. See thread starting with this message: https://cygwin.com/ml/cygwin/2019-03/msg00087.html My proposed workaround is this: https://cygwin.com/ml/cygwin/2019-03/msg00113.html Bill -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: OpenSSH: SSHD daemon (as SYSTEM) is partially broken 2020-02-27 19:34 ` Bill Stewart @ 2020-02-27 23:10 ` TestUser1 2020-02-28 14:53 ` Bill Stewart 0 siblings, 1 reply; 4+ messages in thread From: TestUser1 @ 2020-02-27 23:10 UTC (permalink / raw) To: cygwin So is this expected to work fine in my environment, Windows Server 2016 (OS Version 10.0.14393), without the workaround? Thanks! -- Sent from: http://cygwin.1069669.n5.nabble.com/Cygwin-list-f3.html -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: OpenSSH: SSHD daemon (as SYSTEM) is partially broken 2020-02-27 23:10 ` TestUser1 @ 2020-02-28 14:53 ` Bill Stewart 0 siblings, 0 replies; 4+ messages in thread From: Bill Stewart @ 2020-02-28 14:53 UTC (permalink / raw) To: cygwin On Thu, Feb 27, 2020 at 4:10 PM TestUser1 wrote: So is this expected to work fine in my environment, Windows Server 2016 (OS > Version 10.0.14393), without the workaround? > I can't reproduce on Windows Server 8.1/Server 2012 R2 or later. But you can certainly try the workaround. Bill -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2020-02-28 14:53 UTC | newest] Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2020-02-27 18:09 OpenSSH: SSHD daemon (as SYSTEM) is partially broken n0nc3 2020-02-27 19:34 ` Bill Stewart 2020-02-27 23:10 ` TestUser1 2020-02-28 14:53 ` Bill Stewart
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).