You are not logged in.
Pages: 1
Topic closed
I need ssh with Kerberos and GSSAPI support, to login onto some servers. More specifically, I have the following lines in my ~/.ssh/config for that specific servers:
GSSAPIDelegateCredentials yes
GSSAPIAuthentication yes
StrictHostKeyChecking no
ForwardX11 yes
ForwardX11Trusted yes
PubkeyAuthentication no
GSSAPIKeyExchange yes
GSSAPIRenewalForcesRekey yes
GSSAPITrustDns yesThis did not work with the official OpenSSH version from Arch Linux, since it does not recognize these options:
GSSAPIKeyExchange yes
GSSAPIRenewalForcesRekey yes
GSSAPITrustDns yesHowever, using this package fixed it for me. When all the users of other OS's in my team had troubles logging in, I was always very proud to state that Arch Linux provides a package (not officially, but it's there), that fixes all those problems! ![]()
Those days are past. Now that package does not work for me any more. I get the following error message:
error while loading shared libraries: libldns.so.1I didn't dig deep into what the actual problem is. The package hasn't been maintained for some time, and it is out of date. Hence rather fixing a problem with an old OpenSSH version, I rather get a newer version running. However, when I look at the upstream project, it hasn't received updates for 6 years, either. Not even the pull requests have been pulled/closed.
Now I do not believe that I'm the only one that depends on this additional features of OpenSSH, and hence I believe there must be an up to date package floating around that I could use. Does such a package exist? What software packages do other people use, that are in the same situation? Or do other solutions exist?
All help is much appreciated.
Offline
When you use crud from aur you have to rebuild it yourself when libs it depends on gets bumped.
Evil #archlinux@libera.chat channel op and general support dude.
. files on github, Screenshots, Random pics and the rest
Offline
Thanks. Rebuilding the package worked. But the question remains the same, how can I make this work without using "crud from aur"?
Offline
The package hasn't been maintained for some time, and it is out of date. Hence rather fixing a problem with an old OpenSSH version, I rather get a newer version running.
You do know that the package in the AUR is for a portable version of openssh supporting other OSs. You really don't need that. What you need is just one of the configure flags that happens to be set in that PKGBUILD but not in the PKGBUILD for the main repo package: --with-gssapi
Use ABS to rebuild the main repo package with that flag.
I was always very proud to state that Arch Linux provides a package (not officially, but it's there), that fixes all those problems!
You should be blissful (as ignorance is bliss) when this happens. You should be proud when you actually understand how a fix works or you take the time to fix a problem yourself. In this case the fix is quite trivial and would be obvious if you looked at the PKGBUILDs.
"UNIX is simple and coherent" - Dennis Ritchie; "GNU's Not Unix" - Richard Stallman
Offline
TheGasolineWillBeOurs wrote:The package hasn't been maintained for some time, and it is out of date. Hence rather fixing a problem with an old OpenSSH version, I rather get a newer version running.
You do know that the package in the AUR is for a portable version of openssh supporting other OSs. You really don't need that. What you need is just one of the configure flags that happens to be set in that PKGBUILD but not in the PKGBUILD for the main repo package: --with-gssapi
No, I did not know that. And I still don't understand what this package is used for. It was simply working, and that was good enough for me.
Use ABS to rebuild the main repo package with that flag.
Okay, I did that. I still get the same errors:
/home/basil/.ssh/config: line 24: Bad configuration option: gssapikeyexchange
/home/basil/.ssh/config: line 25: Bad configuration option: gssapirenewalforcesrekey
/home/basil/.ssh/config: line 26: Bad configuration option: gssapitrustdnsTheGasolineWillBeOurs wrote:I was always very proud to state that Arch Linux provides a package (not officially, but it's there), that fixes all those problems!
You should be blissful (as ignorance is bliss) when this happens. You should be proud when you actually understand how a fix works or you take the time to fix a problem yourself. In this case the fix is quite trivial and would be obvious if you looked at the PKGBUILDs.
I did look at the PKGBUILD's, both the official one and the AUR one. Integrated over the last year, for several hours in total, I guess. My lack of understanding comes from not understanding ssh/gssapi. I believed the patches from the AUR package would be essential.
I'm confused as it is still not working. I followed these steps and they seemed easy enough for me to not make a mistake, but I guess I just missed something. Can I check the current ssh install what options it has?
Edit: I just found that when running makepkg, after ./configure, it would tell me
configure: WARNING: unrecognized options: --with-gssapiLast edited by TheGasolineWillBeOurs (2017-01-04 13:25:57)
Offline
Ah, I missed the patches, you'd need those too. In that case it might be trickier as those patches are to work against an old version of the source code.
To me, using an outdated ssh client seems like a very bad idea. Most updates that come to a tool like that are security fixes to keep up with the changing landscape of security threats "out there". Using outdated versions will make you much more vulnerable.
Also, one of the gssapi patches notes that upstream has rejected these because gssapi itself opens up yet other security vulnerabilities.
So using an outdated ssh client with gssapi sounds like a horrible idea. If you must, then perhaps using a virtual machine or nspawn instance would be best. The notes in the patch do give the suggestion that Debian's ssh client uses gssapi, so perhaps a debian instance would be a good start.
"UNIX is simple and coherent" - Dennis Ritchie; "GNU's Not Unix" - Richard Stallman
Offline
Ah, I missed the patches, you'd need those too. In that case it might be trickier as those patches are to work against an old version of the source code.
Yes, I tried it already with the patches. It does not work out of the box.
To me, using an outdated ssh client seems like a very bad idea. Most updates that come to a tool like that are security fixes to keep up with the changing landscape of security threats "out there". Using outdated versions will make you much more vulnerable.
Also, one of the gssapi patches notes that upstream has rejected these because gssapi itself opens up yet other security vulnerabilities.
So using an outdated ssh client with gssapi sounds like a horrible idea. If you must, then perhaps using a virtual machine or nspawn instance would be best. The notes in the patch do give the suggestion that Debian's ssh client uses gssapi, so perhaps a debian instance would be a good start.
I agree with all of that. Seems like I need to dig deeper to solve this problem. Or have a word with the system administrator.
Thank you for the support!
Offline
Hi,
sorry to resurrect this thread..
I was wondering if you managed to solve this problem?
Cheers
Offline
Nope. Actually still using that old AUR package. Are you in the same boat?
Offline
Hey reader in 2020, this post turns up in the google search, posting here in case this helps anyone.
I had the same problem. Arch's openssh does not work out of the box. Even upstream openssh compiled with gssapi support doesn't fully support the option that I'm looking for (GSSAPITrustDNS, which I need to connect to round robin servers, common in particle physics labs.). The AUR package that was supposed to fix this doesn't compile any more. (I'm very new to archlinux -- just installed it last week after trying it out in a VM -- and maybe I was doing something stupid, but it does make sense that the dependencies might have been updated in the last few years.)
I took the openssh package, downloaded the Debian patch that enables GSSAPITrustDNS, and manually added it to openssh. After compiling with the gssapi flag, everything seems to work now. You can check out my changes here: https://github.com/tanmaymudholkar/open … bleKRBAuth
I don't know enough yet to write a pkgbuild and I am generally quite busy. But if there's enough interest from others for this project, I can learn, try to keep the patch more up to date, and contribute my little bit to the community. At least I have a working system now.
Last edited by tmudholk (2020-01-08 23:43:35)
Offline
Please do not necrobump.
Closing this old topic.
tmudholk, a lot has changed in three years. If there is an issue with Arch currently, please feel free to start a new thread.
Last edited by ewaller (2020-01-09 02:37:47)
Nothing is too wonderful to be true, if it be consistent with the laws of nature -- Michael Faraday
The shortest way to ruin a country is to give power to demagogues.— Dionysius of Halicarnassus
---
How to Ask Questions the Smart Way
Offline
Pages: 1
Topic closed