You are not logged in.
I have two boxes running arch, and this used to work perfectly:
from box1:
ssh -X box2; xterm
from box2:
ssh -X box1; xterm
Now after upgrading xorg:
ssh -X box1/2; xterm now returns:
X Error of failed request: BadDrawable (invalid Pixmap or Window parameter)
Major opcode of failed request: 55 (X_CreateGC)
Resource id in failed request: 0x218
Serial number of failed request: 1
Current serial number in output stream: 3
However, things still seem to work if I use ssh -Y. Does anyone have a clue?
Offline
Probably something changed in ssh.conf or sshd.conf - see the man pages to see what the -Y option does that -X doesn't. I think the -Y option has been the correct way (with default conf files) for quite a while.
larch: http://larch.berlios.de
Offline
Same problem here. The man page about -Y:
-X [...]
X11 forwarding should be enabled with caution. Users with the ability to bypass file
permissions on the remote host (for the user's X authorization database) can access
the local X11 display through the forwarded connection. An attacker may then be able
to perform activities such as keystroke monitoring.
For this reason, X11 forwarding is subjected to X11 SECURITY extension restrictions
by default. Please refer to the ssh -Y option and the ForwardX11Trusted directive in
ssh_config(5) for more information.
-Y Enables trusted X11 forwarding. Trusted X11 forwardings are not subjected to the X11
SECURITY extension controls.
Offline
That's what I thought too. ssh -Y is less restrictive and potentially less secure than ssh -X. Does anyone know how to tweak the ssh security options to allow ssh -X to function correctly?
Offline
I've always used SSH with -X to access various machines and servers with Fedora and Ubuntu... never had a problema.
Now with ArchLinux (latest updates) -X doesn't work, and -Y works only in some cases.
I don't thing this is an issue with ssh_config.
Any clues on this?
---
http://cafe-ti.blog.br
Informacao de Pessoas para Pessoas.
Offline
interesting.. maybe this is related with my NX problem... No errors in Log tho, the client seems to connect, but the screen simply disappears...
He hoped and prayed that there wasn't an afterlife. Then he realized there was a contradiction involved here and merely hoped that there wasn't an afterlife.
Douglas Adams
Offline
I need to use:
ForwardX11 yes
ForwardX11Trusted yes
in my config to have X11 forwarding.
Offline
I think that if you use -X then you need to do additional configuration in your X server, not with SSH. Magic cookies or something.
Offline