Re: SSH in Solaris 9
- From
- Konstantin Ischenko (2:463/1124.4)
- To
- Alexander Galanin
- Date
- 2006-08-25T09:22:52Z
- Area
- RU.UNIX.SOLARIS
Hello Alexander!
21 Aug 06 22:12, you wrote to All:
AG> При запуске ssh-клиента(с настройками по умолчанию) выдаётся следующее
AG> и соединение не происходит:
AG> # ssh somehost
AG> unable to initialize mechanism library [/usr/lib/gss/gl/mech_krb5.so]
AG> xmalloc: zero size
AG> #
=== Начало sun.txt ===
=============================================================================
* Area : comp.unix.solaris (comp.unix.solaris)
* From : victorfeng1973@yahoo.com, 2:46/128 (03 May 06 09:46)
* To : All
* Subj : Re: New ssh/sshd patches for Solaris 9
=============================================================================
@RFCID: 1146674776.913172.104780@i39g2000cwa.googlegroups.com
Hi,
I had two errors and I got them resolved with the Sun's help
1.
xmalloc: zero size
2.
"unable to initialize mechanism library
[/usr/lib/gss/gl/mech_krb5.so]"
1.The xmalloc: zero size is a new bug (6402708)
A workaround. by inserting the following in
Your ssh_config file on both client and server
Workaround: inserting the following in
Your ssh_config file on both client and server
StrictHostKeyChecking no
2.For the "unable to initialize mechanism library
[/usr/lib/gss/gl/mech_krb5.so]" (see bug 6392328)
Workarounds
1)
Add to /etc/ssh/ssh_config and /etc/ssh/sshd_config:
GSSAPIAuthentication=no
GSSAPIKeyExchange=no
2) Replace /etc/krb5/krb5.conf with following
# Begining of the file
#
# ident "@(#)krb5.conf 1.4 05/06/08 SMI"
#
# krb5.conf template
# In order to complete this configuration file
# you will need to replace the __<name>__ placeholders
# with appropriate values for your network.
#
[libdefaults]
default_realm = ___default_realm___
[realms]
___default_realm___ = {
kdc = ___master_kdc___
admin_server = ___master_kdc___
}
[domain_realm]
___domainname___ = ___default_realm___
[logging]
default = FILE:/var/krb5/kdc.log
kdc = FILE:/var/krb5/kdc.log
kdc_rotate = {
# How often to rotate kdc.log. Logs will get rotated no more
# often than the period, and less often if the KDC is not used
# frequently.
period = 1d
# how many versions of kdc.log to keep around (kdc.log.0, kdc.log.1,
...)
versions = 10
}
[appdefaults]
kinit = {
renewable = true
forwardable= true
}
# end of file
**Important..In order for new changes to take effect
you must restart sshd process after making your changes
Victor
-+- LuckyGate/Unix 7.02
+ Origin: http://groups.google.com (2:46/128)
=============================================================================
=== Конец sun.txt ===
Konstantin
--- GoldED+/LNX 1.1.5-050821
* Origin: (2:463/1124.4)
SEEN-BY: 400/333 520 450/1024 463/62 68 126 323 384 822 1124 2223 464/36
SEEN-BY: 465/213 466/555 550/5068 4600/103 4621/22 4624/8 4633/2 5000/0 14 26
SEEN-BY: 5000/104 130 170 5000 5002/5002 5004/75 1111 5005/14 5009/14 5010/77
SEEN-BY: 5010/352 5011/13 5012/46 5015/28 5020/545 4441 5021/29 5025/3 5029/34
SEEN-BY: 5030/1957 5035/38 5045/7 5054/1 4 8 9 28 35 37 5055/177 5057/119
SEEN-BY: 5062/10 5064/7 5070/66 5085/13 5090/1029 5095/20 5096/18
PATH: 463/1124 68 5000/5000 5020/545 5054/1 37