Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Secure-Shell
[Top] [All Lists]

Re: Privilege separation user sshd does not exist

Subject: Re: Privilege separation user sshd does not exist
Date: Mon, 04 Jun 2007 21:21:42 -0500
On Tue, 2007-06-05 at 07:54 +1000, Darren Tucker wrote:
Dallas Clement wrote:
'm getting this error when I try to start my cross-compiled OpenSSH sshd
daemon for the first time with privilege separation enabled.
[...]

sshd uses getpwnam() to look up the privsep user, so if that doesn't 
work (eg if your nsswitch.conf or equivalent is broken) then you can get 
that error regardless of what's in /etc/passwd.


You were sure right!  I didn't have any /etc/nsswitch.conf defined at
all, neither did I have any /lib/lib_nss* files either...

Once I added those and also added the following line in my /etc/fstab,
the sshd daemon started to recognize the priv sep user.

However, my ssh login attempts from a remote machine are still failing
for some reason.  I know that the user is valid and the password is
valid since I can login locally.

Here is my sshd output:

debug1: userauth-request for user dallas service ssh-connection method
none
debug1: attempt 0 failures 0
Failed none for dallas from 172.16.1.33 port 58494 ssh2
debug1: userath-request for user dallas service ssh-conection method
password
debug1: attempt 1 failure 1
Failed password for dallas from 172.16.1.33

Can you think of anything else I might be doing wrong for the password
authentication to fail?

This is how I configured the OpenSSH build:

./configure --sysconfdir=/etc/ssh --with-zlib=/home/dallas/zlib_install
--with-ssl-dir=/home/dallas/openssl_install
--host=i686-unknown-linux-gnu --with-privsep-user=sshd --with-shadow
--with-md5-passwords CC=i686-unknown-linux-gnu-gcc

Should I not be specifying md5 password?

Thanks a ton for the help!

<Prev in Thread] Current Thread [Next in Thread>