<html><head></head><body><div style="color:#000; background-color:#fff; font-family:verdana, helvetica, sans-serif;font-size:16px">Hi all,<br id="yui_3_16_0_ym19_1_1481131971764_12695"><br id="yui_3_16_0_ym19_1_1481131971764_12696">I am trying to authenticate an ubuntu Precise (12.06) fully patched system. Its enrolled into a FreeIPA server. The following trace is the output of syslog auth sssd/*.log and full debug (-ddd) from the sshd service.<br id="yui_3_16_0_ym19_1_1481131971764_12697"><br id="yui_3_16_0_ym19_1_1481131971764_12698">I am getting a PAM error at the end of the procedure. Also I cant seem to authenticate against the public ssh key from the id override user.<br id="yui_3_16_0_ym19_1_1481131971764_12699"><br id="yui_3_16_0_ym19_1_1481131971764_12700">I appreciate any help you can send my way.<br id="yui_3_16_0_ym19_1_1481131971764_12701"><br id="yui_3_16_0_ym19_1_1481131971764_12702">Best regards,<br id="yui_3_16_0_ym19_1_1481131971764_12703"><br id="yui_3_16_0_ym19_1_1481131971764_12704">James Harrison<br id="yui_3_16_0_ym19_1_1481131971764_12705">Below is more information<br id="yui_3_16_0_ym19_1_1481131971764_12706"><br id="yui_3_16_0_ym19_1_1481131971764_12707"><br id="yui_3_16_0_ym19_1_1481131971764_12708">root@jamesprecise:~# kinit x_james.harrison@AD.DOMAIN.LOCAL<br id="yui_3_16_0_ym19_1_1481131971764_12709">Password for x_james.harrison@AD.DOMAIN.LOCAL:<br id="yui_3_16_0_ym19_1_1481131971764_12710"><br id="yui_3_16_0_ym19_1_1481131971764_12711">root@jamesprecise:~# klist<br id="yui_3_16_0_ym19_1_1481131971764_12712">Ticket cache: FILE:/tmp/krb5cc_0<br id="yui_3_16_0_ym19_1_1481131971764_12713">Default principal: x_james.harrison@AD.DOMAIN.LOCAL<br id="yui_3_16_0_ym19_1_1481131971764_12714"><br id="yui_3_16_0_ym19_1_1481131971764_12715">Valid starting     Expires            Service principal<br id="yui_3_16_0_ym19_1_1481131971764_12716">07/12/16 17:56:30  08/12/16 03:56:30  krbtgt/AD.DOMAIN.LOCAL@AD.DOMAIN.LOCAL<br id="yui_3_16_0_ym19_1_1481131971764_12717">    renew until 08/12/16 17:56:23<br id="yui_3_16_0_ym19_1_1481131971764_12718"><br id="yui_3_16_0_ym19_1_1481131971764_12719">root@jamesprecise:~# id x_james.harrison@AD.DOMAIN.LOCAL<br id="yui_3_16_0_ym19_1_1481131971764_12720">uid=1039812876(x_james.harrison@ad.domain.local) gid=1039812876(x_james.harrison@ad.domain.local) groups=1039812876(x_james.harrison@ad.domain.local)<br id="yui_3_16_0_ym19_1_1481131971764_12721"><br id="yui_3_16_0_ym19_1_1481131971764_12722">root@pul-lv-ipa-02 ~]# ipa  idoverrideuser-show External_AD_views x_james.harrison@ad.domain.local<br id="yui_3_16_0_ym19_1_1481131971764_12723">  Anchor to override: x_james.harrison@ad.domain.local<br id="yui_3_16_0_ym19_1_1481131971764_12724">  User login: x_james.harrison<br id="yui_3_16_0_ym19_1_1481131971764_12725">  Login shell: /bin/bash<br id="yui_3_16_0_ym19_1_1481131971764_12726">  SSH public key: ssh-rsa<br id="yui_3_16_0_ym19_1_1481131971764_12727">                  AAAAB3NzaC1yc2EAAAADAQABAAABAQDK1pj2U7H9olLs1xKmcmZVEBMWpaHjxF2LttsdfqfQxm810qMru/WsvzHqu0m5Ugu0FYsPxRLQrAEB8WPsPoh5Y0q5qYPgm5aDOZZEXfCPyuRwdQ+XLfQJ3gnGjW4r/XLEiNVpO9eKsFs0ifspNAJ1ndddddddddddddddd7h40rlHlOIqV/z8Omg6XnFBh9dIfiXtpYDOxe+512RpjtHE98s+NfIpUTT7MGNLHB5o/DqFXEJPH7Pp1bKwxWNvfCb5a71vcE695dQ31QYVYwpSwFmFogewgpV/OCb+S4SUdUq1xg0fmkhYr3d4UXFr91MDimyOBWk9Aai7NkOHPszmHJp<br id="yui_3_16_0_ym19_1_1481131971764_12728">                  JamesHarrison<br id="yui_3_16_0_ym19_1_1481131971764_12729"><br id="yui_3_16_0_ym19_1_1481131971764_12730"><br id="yui_3_16_0_ym19_1_1481131971764_12731">Here are the software versions:<br id="yui_3_16_0_ym19_1_1481131971764_12732"><br id="yui_3_16_0_ym19_1_1481131971764_12733">root@jamesprecise:# dpkg -l | grep -i freeipa<br id="yui_3_16_0_ym19_1_1481131971764_12734">ii  freeipa-client                             3.3.4-0ubuntu3.1~precise0.1        FreeIPA centralized identity framework -- client<br id="yui_3_16_0_ym19_1_1481131971764_12735">ii  libipa-hbac0                               1.11.5-1ubuntu3~precise1           FreeIPA HBAC Evaluator library<br id="yui_3_16_0_ym19_1_1481131971764_12736">ii  python-freeipa                             3.3.4-0ubuntu3.1~precise0.1        FreeIPA centralized identity framework -- python modules<br id="yui_3_16_0_ym19_1_1481131971764_12737">ii  python-libipa-hbac                         1.11.5-1ubuntu3~precise1           Python bindings for the FreeIPA HBAC Evaluator library<br id="yui_3_16_0_ym19_1_1481131971764_12738"><br id="yui_3_16_0_ym19_1_1481131971764_12739">root@jamesprecise:# dpkg -l | grep -i openssh-server<br id="yui_3_16_0_ym19_1_1481131971764_12740">ii  openssh-server                             1:5.9p1-5ubuntu1.10                secure shell (SSH) server, for secure access from remote machines<br id="yui_3_16_0_ym19_1_1481131971764_12741"><br id="yui_3_16_0_ym19_1_1481131971764_12742"><br id="yui_3_16_0_ym19_1_1481131971764_12743">root@jamesprecise:/var/log# dpkg -l | grep -i sssd<br id="yui_3_16_0_ym19_1_1481131971764_12744">ii  libsss-idmap0                              1.11.5-1ubuntu3~precise1           ID mapping library for SSSD<br id="yui_3_16_0_ym19_1_1481131971764_12745">ii  sssd                                       1.11.5-1ubuntu3~precise1           System Security Services Daemon -- metapackage<br id="yui_3_16_0_ym19_1_1481131971764_12746">ii  sssd-ad                                    1.11.5-1ubuntu3~precise1           System Security Services Daemon -- Active Directory back end<br id="yui_3_16_0_ym19_1_1481131971764_12747">ii  sssd-ad-common                             1.11.5-1ubuntu3~precise1           System Security Services Daemon -- PAC responder<br id="yui_3_16_0_ym19_1_1481131971764_12748">ii  sssd-common                                1.11.5-1ubuntu3~precise1           System Security Services Daemon -- common files<br id="yui_3_16_0_ym19_1_1481131971764_12749">ii  sssd-ipa                                   1.11.5-1ubuntu3~precise1           System Security Services Daemon -- IPA back end<br id="yui_3_16_0_ym19_1_1481131971764_12750">ii  sssd-krb5                                  1.11.5-1ubuntu3~precise1           System Security Services Daemon -- Kerberos back end<br id="yui_3_16_0_ym19_1_1481131971764_12751">ii  sssd-krb5-common                           1.11.5-1ubuntu3~precise1           System Security Services Daemon -- Kerberos helpers<br id="yui_3_16_0_ym19_1_1481131971764_12752">ii  sssd-ldap                                  1.11.5-1ubuntu3~precise1           System Security Services Daemon -- LDAP back end<br id="yui_3_16_0_ym19_1_1481131971764_12753">ii  sssd-proxy                                 1.11.5-1ubuntu3~precise1           System Security Services Daemon -- proxy back end<br id="yui_3_16_0_ym19_1_1481131971764_12754">ii  sudo                                       1.8.9p5-1ubuntu1.1~sssd1           Provide limited super user privileges to specific users<br id="yui_3_16_0_ym19_1_1481131971764_12755"><br id="yui_3_16_0_ym19_1_1481131971764_12756">Ubuntu PPAs:<br id="yui_3_16_0_ym19_1_1481131971764_12757">root@jamesprecise:~# ls -l /etc/apt/sources.list.d/<br id="yui_3_16_0_ym19_1_1481131971764_12759">total 16<br id="yui_3_16_0_ym19_1_1481131971764_12760">-rw-r--r-- 1 root root 65 Dec  7 08:48 freeipa-ppa-precise.list<br id="yui_3_16_0_ym19_1_1481131971764_12761">-rw-r--r-- 1 root root 61 Dec  7 08:48 ppa_freeipa_ppa_precise.list<br id="yui_3_16_0_ym19_1_1481131971764_12762">-rw-r--r-- 1 root root 62 Dec  7 08:48 ppa_sssd_updates_precise.list<br id="yui_3_16_0_ym19_1_1481131971764_12763">-rw-r--r-- 1 root root 66 Dec  7 08:48 sssd-updates-precise.list<br id="yui_3_16_0_ym19_1_1481131971764_12764"><br id="yui_3_16_0_ym19_1_1481131971764_12765">cat /etc/pam.d/common-session<br id="yui_3_16_0_ym19_1_1481131971764_12766">session    [default=1]            pam_permit.so<br id="yui_3_16_0_ym19_1_1481131971764_12768">session    requisite            pam_deny.so<br id="yui_3_16_0_ym19_1_1481131971764_12769">session    required            pam_permit.so<br id="yui_3_16_0_ym19_1_1481131971764_12770">session optional            pam_umask.so<br id="yui_3_16_0_ym19_1_1481131971764_12771">session    required                        pam_mkhomedir.so umask=0022 skel=/etc/skel<br id="yui_3_16_0_ym19_1_1481131971764_12772">session    required    pam_unix.so<br id="yui_3_16_0_ym19_1_1481131971764_12773">session    optional            pam_sss.so<br id="yui_3_16_0_ym19_1_1481131971764_12774">session    [success=ok default=ignore]    pam_ldap.so minimum_uid=1000<br id="yui_3_16_0_ym19_1_1481131971764_12775">root@jamesprecise:~#<br id="yui_3_16_0_ym19_1_1481131971764_12776"><br id="yui_3_16_0_ym19_1_1481131971764_12777">root@jamesprecise:~# cat /etc/pam.d/common-auth<br id="yui_3_16_0_ym19_1_1481131971764_12778">auth    [success=3 default=ignore]    pam_unix.so nullok_secure<br id="yui_3_16_0_ym19_1_1481131971764_12779">auth    [success=2 default=ignore]    pam_sss.so use_first_pass<br id="yui_3_16_0_ym19_1_1481131971764_12780">auth    [success=1 default=ignore]    pam_ldap.so minimum_uid=1000 use_first_pass<br id="yui_3_16_0_ym19_1_1481131971764_12781">auth    requisite            pam_deny.so<br id="yui_3_16_0_ym19_1_1481131971764_12782">auth    required            pam_permit.so<br id="yui_3_16_0_ym19_1_1481131971764_12783"><br id="yui_3_16_0_ym19_1_1481131971764_12784">root@jamesprecise:~# cat /etc/pam.d/common-account<br id="yui_3_16_0_ym19_1_1481131971764_12785">account    [success=1 new_authtok_reqd=done default=ignore]    pam_unix.so<br id="yui_3_16_0_ym19_1_1481131971764_12786">account    requisite            pam_deny.so<br id="yui_3_16_0_ym19_1_1481131971764_12787">account    required            pam_permit.so<br id="yui_3_16_0_ym19_1_1481131971764_12788">account    sufficient            pam_localuser.so<br id="yui_3_16_0_ym19_1_1481131971764_12789">account    [default=bad success=ok user_unknown=ignore]    pam_sss.so<br id="yui_3_16_0_ym19_1_1481131971764_12790">account    [success=ok new_authtok_reqd=done ignore=ignore user_unknown=ignore authinfo_unavail=ignore default=bad]    pam_ldap.so minimum_uid=1000<br id="yui_3_16_0_ym19_1_1481131971764_12791"><br id="yui_3_16_0_ym19_1_1481131971764_12792">root@jamesprecise:~# cat /etc/krb5.conf<br id="yui_3_16_0_ym19_1_1481131971764_12793">#File modified by ipa-client-install<br id="yui_3_16_0_ym19_1_1481131971764_12794"><br id="yui_3_16_0_ym19_1_1481131971764_12795">includedir /var/lib/sss/pubconf/krb5.include.d/<br id="yui_3_16_0_ym19_1_1481131971764_12796"><br id="yui_3_16_0_ym19_1_1481131971764_12797">[libdefaults]<br id="yui_3_16_0_ym19_1_1481131971764_12798">  default_realm = FREEIPA-REALM<br id="yui_3_16_0_ym19_1_1481131971764_12799">  dns_lookup_realm = true<br id="yui_3_16_0_ym19_1_1481131971764_12800">  dns_lookup_kdc = true<br id="yui_3_16_0_ym19_1_1481131971764_12801">  rdns = false<br id="yui_3_16_0_ym19_1_1481131971764_12802">  ticket_lifetime = 24h<br id="yui_3_16_0_ym19_1_1481131971764_12803">  forwardable = yes<br id="yui_3_16_0_ym19_1_1481131971764_12804">#  ignore_acceptor_hostname = true<br id="yui_3_16_0_ym19_1_1481131971764_12805"><br id="yui_3_16_0_ym19_1_1481131971764_12806">[realms]<br id="yui_3_16_0_ym19_1_1481131971764_12807">  FREEIPA-REALM = {<br id="yui_3_16_0_ym19_1_1481131971764_12808">    pkinit_anchors = FILE:/etc/ipa/ca.crt<br id="yui_3_16_0_ym19_1_1481131971764_12809">  }<br id="yui_3_16_0_ym19_1_1481131971764_12810"><br id="yui_3_16_0_ym19_1_1481131971764_12811">[domain_realm]<br id="yui_3_16_0_ym19_1_1481131971764_12812">  .freeipa.domain.com = FREEIPA-REALM<br id="yui_3_16_0_ym19_1_1481131971764_12813">  freeipa.domain.com = FREEIPA-REALM<br id="yui_3_16_0_ym19_1_1481131971764_12814"><br id="yui_3_16_0_ym19_1_1481131971764_12815">root@jamesprecise:~# cat /etc/sssd/sssd.conf<br id="yui_3_16_0_ym19_1_1481131971764_12816">[domain/freeipa.domain.com]<br id="yui_3_16_0_ym19_1_1481131971764_12817">cache_credentials = True<br id="yui_3_16_0_ym19_1_1481131971764_12818">krb5_store_password_if_offline = True<br id="yui_3_16_0_ym19_1_1481131971764_12819">ipa_domain = freeipa.domain.com<br id="yui_3_16_0_ym19_1_1481131971764_12820">id_provider = ipa<br id="yui_3_16_0_ym19_1_1481131971764_12821">auth_provider = ipa<br id="yui_3_16_0_ym19_1_1481131971764_12822">access_provider = ipa<br id="yui_3_16_0_ym19_1_1481131971764_12823">ipa_hostname = jamesprecise.freeipa.domain.com<br id="yui_3_16_0_ym19_1_1481131971764_12824">chpass_provider = ipa<br id="yui_3_16_0_ym19_1_1481131971764_12825">ipa_server = tx-lv-ipa-02.freeipa.domain.com<br id="yui_3_16_0_ym19_1_1481131971764_12826">ldap_tls_cacert = /etc/ipa/ca.crt<br id="yui_3_16_0_ym19_1_1481131971764_12827">debug_level = 5<br id="yui_3_16_0_ym19_1_1481131971764_12828"><br id="yui_3_16_0_ym19_1_1481131971764_12829">[sssd]<br id="yui_3_16_0_ym19_1_1481131971764_12830">services = nss, pam, ssh, sudo<br id="yui_3_16_0_ym19_1_1481131971764_12831">config_file_version = 2<br id="yui_3_16_0_ym19_1_1481131971764_12832">domains = freeipa.domain.com<br id="yui_3_16_0_ym19_1_1481131971764_12833"><br id="yui_3_16_0_ym19_1_1481131971764_12834">[nss]<br id="yui_3_16_0_ym19_1_1481131971764_12836"><br id="yui_3_16_0_ym19_1_1481131971764_12837">[pam]<br id="yui_3_16_0_ym19_1_1481131971764_12838"><br id="yui_3_16_0_ym19_1_1481131971764_12839">[sudo]<br id="yui_3_16_0_ym19_1_1481131971764_12840"><br id="yui_3_16_0_ym19_1_1481131971764_12841">[autofs]<br id="yui_3_16_0_ym19_1_1481131971764_12842"><br id="yui_3_16_0_ym19_1_1481131971764_12843">[ssh]<br id="yui_3_16_0_ym19_1_1481131971764_12844"><br id="yui_3_16_0_ym19_1_1481131971764_12845">[pac]<br id="yui_3_16_0_ym19_1_1481131971764_12846"><br id="yui_3_16_0_ym19_1_1481131971764_12847">Below if the trace output as appeared on my screen:<br id="yui_3_16_0_ym19_1_1481131971764_12848"><br id="yui_3_16_0_ym19_1_1481131971764_12849">root@jamesprecise:/var/log# /usr/sbin/sshd -ddd<br id="yui_3_16_0_ym19_1_1481131971764_12850">debug2: load_server_config: filename /etc/ssh/sshd_config<br id="yui_3_16_0_ym19_1_1481131971764_12851">debug2: load_server_config: done config len = 773<br id="yui_3_16_0_ym19_1_1481131971764_12852">debug2: parse_server_config: config /etc/ssh/sshd_config len 773<br id="yui_3_16_0_ym19_1_1481131971764_12853">debug3: /etc/ssh/sshd_config:5 setting Port 2230<br id="yui_3_16_0_ym19_1_1481131971764_12854">debug3: /etc/ssh/sshd_config:9 setting Protocol 2<br id="yui_3_16_0_ym19_1_1481131971764_12855">debug3: /etc/ssh/sshd_config:11 setting HostKey /etc/ssh/ssh_host_rsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12856">debug3: /etc/ssh/sshd_config:12 setting HostKey /etc/ssh/ssh_host_dsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12857">debug3: /etc/ssh/sshd_config:13 setting HostKey /etc/ssh/ssh_host_ecdsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12858">debug3: /etc/ssh/sshd_config:16 setting UsePrivilegeSeparation yes<br id="yui_3_16_0_ym19_1_1481131971764_12859">debug3: /etc/ssh/sshd_config:19 setting KeyRegenerationInterval 3600<br id="yui_3_16_0_ym19_1_1481131971764_12860">debug3: /etc/ssh/sshd_config:20 setting ServerKeyBits 1024<br id="yui_3_16_0_ym19_1_1481131971764_12861">debug3: /etc/ssh/sshd_config:23 setting SyslogFacility AUTH<br id="yui_3_16_0_ym19_1_1481131971764_12862">debug3: /etc/ssh/sshd_config:24 setting LogLevel VERBOSE<br id="yui_3_16_0_ym19_1_1481131971764_12863">debug3: /etc/ssh/sshd_config:27 setting LoginGraceTime 120<br id="yui_3_16_0_ym19_1_1481131971764_12864">debug3: /etc/ssh/sshd_config:28 setting PermitRootLogin without-password<br id="yui_3_16_0_ym19_1_1481131971764_12865">debug3: /etc/ssh/sshd_config:29 setting StrictModes yes<br id="yui_3_16_0_ym19_1_1481131971764_12866">debug3: /etc/ssh/sshd_config:31 setting RSAAuthentication yes<br id="yui_3_16_0_ym19_1_1481131971764_12867">debug3: /etc/ssh/sshd_config:32 setting AuthorizedKeysFile %h/.ssh/authorized_keys<br id="yui_3_16_0_ym19_1_1481131971764_12868">debug3: /etc/ssh/sshd_config:35 setting IgnoreRhosts yes<br id="yui_3_16_0_ym19_1_1481131971764_12869">debug3: /etc/ssh/sshd_config:37 setting RhostsRSAAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12870">debug3: /etc/ssh/sshd_config:39 setting HostbasedAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12871">debug3: /etc/ssh/sshd_config:44 setting PermitEmptyPasswords no<br id="yui_3_16_0_ym19_1_1481131971764_12872">debug3: /etc/ssh/sshd_config:48 setting ChallengeResponseAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12873">debug3: /etc/ssh/sshd_config:51 setting PasswordAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12874">debug3: /etc/ssh/sshd_config:63 setting X11Forwarding no<br id="yui_3_16_0_ym19_1_1481131971764_12875">debug3: /etc/ssh/sshd_config:64 setting X11DisplayOffset 10<br id="yui_3_16_0_ym19_1_1481131971764_12876">debug3: /etc/ssh/sshd_config:65 setting PrintMotd no<br id="yui_3_16_0_ym19_1_1481131971764_12877">debug3: /etc/ssh/sshd_config:66 setting PrintLastLog yes<br id="yui_3_16_0_ym19_1_1481131971764_12878">debug3: /etc/ssh/sshd_config:67 setting TCPKeepAlive yes<br id="yui_3_16_0_ym19_1_1481131971764_12879">debug3: /etc/ssh/sshd_config:74 setting AcceptEnv LANG LC_*<br id="yui_3_16_0_ym19_1_1481131971764_12880">debug3: /etc/ssh/sshd_config:76 setting Subsystem sftp /usr/lib/openssh/sftp-server<br id="yui_3_16_0_ym19_1_1481131971764_12881">debug3: /etc/ssh/sshd_config:87 setting PubkeyAuthentication yes<br id="yui_3_16_0_ym19_1_1481131971764_12882">debug3: /etc/ssh/sshd_config:88 setting UsePAM yes<br id="yui_3_16_0_ym19_1_1481131971764_12883">debug1: sshd version OpenSSH_5.9p1 Debian-5ubuntu1.10<br id="yui_3_16_0_ym19_1_1481131971764_12884">debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12885">debug1: read PEM private key done: type RSA<br id="yui_3_16_0_ym19_1_1481131971764_12886">debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_12887">debug1: Checking blacklist file /etc/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_12888">debug1: private host key: #0 type 1 RSA<br id="yui_3_16_0_ym19_1_1481131971764_12889">debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12890">debug1: read PEM private key done: type DSA<br id="yui_3_16_0_ym19_1_1481131971764_12891">debug1: Checking blacklist file /usr/share/ssh/blacklist.DSA-1024<br id="yui_3_16_0_ym19_1_1481131971764_12892">debug1: Checking blacklist file /etc/ssh/blacklist.DSA-1024<br id="yui_3_16_0_ym19_1_1481131971764_12893">debug1: private host key: #1 type 2 DSA<br id="yui_3_16_0_ym19_1_1481131971764_12894">debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12895">debug1: read PEM private key done: type ECDSA<br id="yui_3_16_0_ym19_1_1481131971764_12896">debug1: Checking blacklist file /usr/share/ssh/blacklist.ECDSA-256<br id="yui_3_16_0_ym19_1_1481131971764_12897">debug1: Checking blacklist file /etc/ssh/blacklist.ECDSA-256<br id="yui_3_16_0_ym19_1_1481131971764_12898">debug1: private host key: #2 type 3 ECDSA<br id="yui_3_16_0_ym19_1_1481131971764_12899">debug1: rexec_argv[0]='/usr/sbin/sshd'<br id="yui_3_16_0_ym19_1_1481131971764_12900">debug1: rexec_argv[1]='-ddd'<br id="yui_3_16_0_ym19_1_1481131971764_12901">debug3: oom_adjust_setup<br id="yui_3_16_0_ym19_1_1481131971764_12902">Set /proc/self/oom_score_adj from 0 to -1000<br id="yui_3_16_0_ym19_1_1481131971764_12903">debug2: fd 3 setting O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_12904">debug1: Bind to port 2230 on 0.0.0.0.<br id="yui_3_16_0_ym19_1_1481131971764_12905">Server listening on 0.0.0.0 port 2230.<br id="yui_3_16_0_ym19_1_1481131971764_12906">debug2: fd 4 setting O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_12907">debug3: sock_set_v6only: set socket 4 IPV6_V6ONLY<br id="yui_3_16_0_ym19_1_1481131971764_12908">debug1: Bind to port 2230 on ::.<br id="yui_3_16_0_ym19_1_1481131971764_12909">Server listening on :: port 2230.<br id="yui_3_16_0_ym19_1_1481131971764_12910">debug3: fd 5 is not O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_12911">debug1: Server will not fork when running in debugging mode.<br id="yui_3_16_0_ym19_1_1481131971764_12912">debug3: send_rexec_state: entering fd = 8 config len 773<br id="yui_3_16_0_ym19_1_1481131971764_12913">debug3: ssh_msg_send: type 0<br id="yui_3_16_0_ym19_1_1481131971764_12914">debug3: send_rexec_state: done<br id="yui_3_16_0_ym19_1_1481131971764_12915">debug1: rexec start in 5 out 5 newsock 5 pipe -1 sock 8<br id="yui_3_16_0_ym19_1_1481131971764_12916"><br id="yui_3_16_0_ym19_1_1481131971764_12917">==> auth.log <==<br id="yui_3_16_0_ym19_1_1481131971764_12918">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: recv_rexec_state: entering fd = 5<br id="yui_3_16_0_ym19_1_1481131971764_12919">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: ssh_msg_recv entering<br id="yui_3_16_0_ym19_1_1481131971764_12920">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: recv_rexec_state: done<br id="yui_3_16_0_ym19_1_1481131971764_12921">Dec  7 17:31:47 jamesprecise sshd[1839]: debug2: parse_server_config: config rexec len 773<br id="yui_3_16_0_ym19_1_1481131971764_12922">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:5 setting Port 2230<br id="yui_3_16_0_ym19_1_1481131971764_12923">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:9 setting Protocol 2<br id="yui_3_16_0_ym19_1_1481131971764_12924">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:11 setting HostKey /etc/ssh/ssh_host_rsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12925">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:12 setting HostKey /etc/ssh/ssh_host_dsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12926">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:13 setting HostKey /etc/ssh/ssh_host_ecdsa_key<br id="yui_3_16_0_ym19_1_1481131971764_12927">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:16 setting UsePrivilegeSeparation yes<br id="yui_3_16_0_ym19_1_1481131971764_12928">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:19 setting KeyRegenerationInterval 3600<br id="yui_3_16_0_ym19_1_1481131971764_12929">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:20 setting ServerKeyBits 1024<br id="yui_3_16_0_ym19_1_1481131971764_12930">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:23 setting SyslogFacility AUTH<br id="yui_3_16_0_ym19_1_1481131971764_12931">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:24 setting LogLevel VERBOSE<br id="yui_3_16_0_ym19_1_1481131971764_12932">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:27 setting LoginGraceTime 120<br id="yui_3_16_0_ym19_1_1481131971764_12933">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:28 setting PermitRootLogin without-password<br id="yui_3_16_0_ym19_1_1481131971764_12934">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:29 setting StrictModes yes<br id="yui_3_16_0_ym19_1_1481131971764_12935">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:31 setting RSAAuthentication yes<br id="yui_3_16_0_ym19_1_1481131971764_12936">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:32 setting AuthorizedKeysFile %h/.ssh/authorized_keys<br id="yui_3_16_0_ym19_1_1481131971764_12937">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:35 setting IgnoreRhosts yes<br id="yui_3_16_0_ym19_1_1481131971764_12938">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:37 setting RhostsRSAAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12939">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:39 setting HostbasedAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12940">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:44 setting PermitEmptyPasswords no<br id="yui_3_16_0_ym19_1_1481131971764_12941">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:48 setting ChallengeResponseAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12942">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:51 setting PasswordAuthentication no<br id="yui_3_16_0_ym19_1_1481131971764_12943">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:63 setting X11Forwarding no<br id="yui_3_16_0_ym19_1_1481131971764_12944">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:64 setting X11DisplayOffset 10<br id="yui_3_16_0_ym19_1_1481131971764_12945">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:65 setting PrintMotd no<br id="yui_3_16_0_ym19_1_1481131971764_12946">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:66 setting PrintLastLog yes<br id="yui_3_16_0_ym19_1_1481131971764_12947">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:67 setting TCPKeepAlive yes<br id="yui_3_16_0_ym19_1_1481131971764_12948">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:74 setting AcceptEnv LANG LC_*<br id="yui_3_16_0_ym19_1_1481131971764_12949">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:76 setting Subsystem sftp /usr/lib/openssh/sftp-server<br id="yui_3_16_0_ym19_1_1481131971764_12950">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:87 setting PubkeyAuthentication yes<br id="yui_3_16_0_ym19_1_1481131971764_12951">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: rexec:88 setting UsePAM yes<br id="yui_3_16_0_ym19_1_1481131971764_12952">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: sshd version OpenSSH_5.9p1 Debian-5ubuntu1.10<br id="yui_3_16_0_ym19_1_1481131971764_12953">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12954">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: read PEM private key done: type RSA<br id="yui_3_16_0_ym19_1_1481131971764_12955">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_12956">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /etc/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_12957">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: private host key: #0 type 1 RSA<br id="yui_3_16_0_ym19_1_1481131971764_12958">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12959">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: read PEM private key done: type DSA<br id="yui_3_16_0_ym19_1_1481131971764_12960">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /usr/share/ssh/blacklist.DSA-1024<br id="yui_3_16_0_ym19_1_1481131971764_12961">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /etc/ssh/blacklist.DSA-1024<br id="yui_3_16_0_ym19_1_1481131971764_12962">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: private host key: #1 type 2 DSA<br id="yui_3_16_0_ym19_1_1481131971764_12963">Dec  7 17:31:47 jamesprecise sshd[1839]: debug3: Incorrect RSA1 identifier<br id="yui_3_16_0_ym19_1_1481131971764_12964">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: read PEM private key done: type ECDSA<br id="yui_3_16_0_ym19_1_1481131971764_12965">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /usr/share/ssh/blacklist.ECDSA-256<br id="yui_3_16_0_ym19_1_1481131971764_12966">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: Checking blacklist file /etc/ssh/blacklist.ECDSA-256<br id="yui_3_16_0_ym19_1_1481131971764_12967">Dec  7 17:31:47 jamesprecise sshd[1839]: debug1: private host key: #2 type 3 ECDSA<br id="yui_3_16_0_ym19_1_1481131971764_12968">debug1: inetd sockets after dupping: 3, 3<br id="yui_3_16_0_ym19_1_1481131971764_12969">Connection from 10.10.10.10 port 45036<br id="yui_3_16_0_ym19_1_1481131971764_12970">debug1: Client protocol version 2.0; client software version OpenSSH_7.2p2 Ubuntu-4ubuntu2.1<br id="yui_3_16_0_ym19_1_1481131971764_12971">debug1: match: OpenSSH_7.2p2 Ubuntu-4ubuntu2.1 pat OpenSSH*<br id="yui_3_16_0_ym19_1_1481131971764_12972">debug1: Enabling compatibility mode for protocol 2.0<br id="yui_3_16_0_ym19_1_1481131971764_12973">debug1: Local version string SSH-2.0-OpenSSH_5.9p1 Debian-5ubuntu1.10<br id="yui_3_16_0_ym19_1_1481131971764_12974">debug2: fd 3 setting O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_12975">debug2: Network child is on pid 1840<br id="yui_3_16_0_ym19_1_1481131971764_12976">debug3: preauth child monitor started<br id="yui_3_16_0_ym19_1_1481131971764_12977">debug3: privsep user:group 105:65534 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12978">debug1: permanently_set_uid: 105/65534 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12979">debug1: list_hostkey_types: ssh-rsa,ssh-dss,ecdsa-sha2-nistp256 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12980">debug1: SSH2_MSG_KEXINIT sent [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12981">debug1: SSH2_MSG_KEXINIT received [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12982">debug2: kex_parse_kexinit: ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12983">debug2: kex_parse_kexinit: ssh-rsa,ssh-dss,ecdsa-sha2-nistp256 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12984">debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12985">debug2: kex_parse_kexinit: aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12986">debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-sha2-256,hmac-sha2-256-96,hmac-sha2-512,hmac-sha2-512-96,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12987">debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-sha2-256,hmac-sha2-256-96,hmac-sha2-512,hmac-sha2-512-96,hmac-ripemd160,hmac-ripemd160@openssh.com,hmac-sha1-96,hmac-md5-96 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12988">debug2: kex_parse_kexinit: none,zlib@openssh.com [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12989">debug2: kex_parse_kexinit: none,zlib@openssh.com [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12990">debug2: kex_parse_kexinit:  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12991">debug2: kex_parse_kexinit:  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12992">debug2: kex_parse_kexinit: first_kex_follows 0  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12993">debug2: kex_parse_kexinit: reserved 0  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12994">debug2: kex_parse_kexinit: curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,ext-info-c [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12995">debug2: kex_parse_kexinit: ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12996">debug2: kex_parse_kexinit: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12997">debug2: kex_parse_kexinit: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-cbc,aes192-cbc,aes256-cbc,3des-cbc [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12998">debug2: kex_parse_kexinit: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_12999">debug2: kex_parse_kexinit: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13000">debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13001">debug2: kex_parse_kexinit: none,zlib@openssh.com,zlib [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13002">debug2: kex_parse_kexinit:  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13003">debug2: kex_parse_kexinit:  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13004">debug2: kex_parse_kexinit: first_kex_follows 0  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13005">debug2: kex_parse_kexinit: reserved 0  [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13006">debug2: mac_setup: found umac-64@openssh.com [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13007">debug1: kex: client->server aes128-ctr umac-64@openssh.com none [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13008">debug2: mac_setup: found umac-64@openssh.com [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13009">debug1: kex: server->client aes128-ctr umac-64@openssh.com none [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13010">debug1: expecting SSH2_MSG_KEX_ECDH_INIT [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13011">debug3: mm_key_sign entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13012">debug3: mm_request_send entering: type 5 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13013">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13014">debug3: monitor_read: checking request 5<br id="yui_3_16_0_ym19_1_1481131971764_13015">debug3: mm_answer_sign<br id="yui_3_16_0_ym19_1_1481131971764_13016">debug3: mm_answer_sign: signature 0x7fcb152fe1a0(100)<br id="yui_3_16_0_ym19_1_1481131971764_13017">debug3: mm_request_send entering: type 6<br id="yui_3_16_0_ym19_1_1481131971764_13018">debug2: monitor_read: 5 used once, disabling now<br id="yui_3_16_0_ym19_1_1481131971764_13019">debug3: mm_key_sign: waiting for MONITOR_ANS_SIGN [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13020">debug3: mm_request_receive_expect entering: type 6 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13021">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13022">debug2: kex_derive_keys [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13023">debug2: set_newkeys: mode 1 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13024">debug1: SSH2_MSG_NEWKEYS sent [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13025">debug1: expecting SSH2_MSG_NEWKEYS [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13026">debug2: set_newkeys: mode 0 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13027">debug1: SSH2_MSG_NEWKEYS received [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13028">debug1: KEX done [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13029">debug1: userauth-request for user a_aaaaaaa.aaaaa@xxxxxxx.xxxx service ssh-connection method none [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13030">debug1: attempt 0 failures 0 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13031">debug3: mm_getpwnamallow entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13032">debug3: mm_request_send entering: type 7 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13033">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13034">debug3: monitor_read: checking request 7<br id="yui_3_16_0_ym19_1_1481131971764_13035">debug3: mm_answer_pwnamallow<br id="yui_3_16_0_ym19_1_1481131971764_13036">debug3: Trying to reverse map address 10.10.10.10.<br id="yui_3_16_0_ym19_1_1481131971764_13037">debug2: parse_server_config: config reprocess config len 773<br id="yui_3_16_0_ym19_1_1481131971764_13038">debug3: mm_answer_pwnamallow: sending MONITOR_ANS_PWNAM: 1<br id="yui_3_16_0_ym19_1_1481131971764_13039">debug3: mm_request_send entering: type 8<br id="yui_3_16_0_ym19_1_1481131971764_13040">debug2: monitor_read: 7 used once, disabling now<br id="yui_3_16_0_ym19_1_1481131971764_13041">debug3: mm_getpwnamallow: waiting for MONITOR_ANS_PWNAM [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13042">debug3: mm_request_receive_expect entering: type 8 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13043">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13044">debug2: input_userauth_request: setting up authctxt for a_aaaaaaa.aaaaa@xxxxxxx.xxxx [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13045">debug3: mm_start_pam entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13046">debug3: mm_request_send entering: type 50 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13047">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13048">debug3: monitor_read: checking request 50<br id="yui_3_16_0_ym19_1_1481131971764_13049">debug1: PAM: initializing for "a_aaaaaaa.aaaaa@xxxxxxx.xxxx"<br id="yui_3_16_0_ym19_1_1481131971764_13050">debug1: PAM: setting PAM_RHOST to "10.10.10.10"<br id="yui_3_16_0_ym19_1_1481131971764_13051">debug1: PAM: setting PAM_TTY to "ssh"<br id="yui_3_16_0_ym19_1_1481131971764_13052">debug2: monitor_read: 50 used once, disabling now<br id="yui_3_16_0_ym19_1_1481131971764_13053">debug3: mm_inform_authserv entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13054">debug3: mm_request_send entering: type 3 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13055">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13056">debug3: monitor_read: checking request 3<br id="yui_3_16_0_ym19_1_1481131971764_13057">debug3: mm_answer_authserv: service=ssh-connection, style=, role=<br id="yui_3_16_0_ym19_1_1481131971764_13058">debug2: monitor_read: 3 used once, disabling now<br id="yui_3_16_0_ym19_1_1481131971764_13059">debug2: input_userauth_request: try method none [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13060">debug1: userauth-request for user a_aaaaaaa.aaaaa@xxxxxxx.xxxx service ssh-connection method publickey [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13061">debug1: attempt 1 failures 0 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13062">debug2: input_userauth_request: try method publickey [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13063">debug1: test whether pkalg/pkblob are acceptable [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13064">debug3: mm_key_allowed entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13065">debug3: mm_request_send entering: type 21 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13066">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13067">debug3: monitor_read: checking request 21<br id="yui_3_16_0_ym19_1_1481131971764_13068">debug3: mm_answer_keyallowed entering<br id="yui_3_16_0_ym19_1_1481131971764_13069">debug3: mm_answer_keyallowed: key_from_blob: 0x7fcb15302ec0<br id="yui_3_16_0_ym19_1_1481131971764_13070">debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_13071">debug1: Checking blacklist file /etc/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_13072">debug1: temporarily_use_uid: 1039812876/1039812876 (e=0/0)<br id="yui_3_16_0_ym19_1_1481131971764_13073"><br id="yui_3_16_0_ym19_1_1481131971764_13074">==> sssd/sssd_freeipa.domain.com.log <==<br id="yui_3_16_0_ym19_1_1481131971764_13075">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [be_get_account_info] (0x0100): Got request for [4099][1][name=a_aaaaaaa.aaaaa]<br id="yui_3_16_0_ym19_1_1481131971764_13076">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [acctinfo_callback] (0x0100): Request processed. Returned 3,95,Account info lookup failed<br id="yui_3_16_0_ym19_1_1481131971764_13077">debug1: trying public key file /home/xxxxxxx.xxxx/a_aaaaaaa.aaaaa/.ssh/authorized_keys<br id="yui_3_16_0_ym19_1_1481131971764_13078">debug1: fd 8 clearing O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_13079">debug1: matching key found: file /home/xxxxxxx.xxxx/a_aaaaaaa.aaaaa/.ssh/authorized_keys, line 8<br id="yui_3_16_0_ym19_1_1481131971764_13080">Found matching RSA key: a6:61:f3:d1:f6:87:4f:e2:27:49:88:f8:09:93:11:27<br id="yui_3_16_0_ym19_1_1481131971764_13081">debug1: restore_uid: 0/0<br id="yui_3_16_0_ym19_1_1481131971764_13082">debug3: mm_answer_keyallowed: key 0x7fcb15302ec0 is allowed<br id="yui_3_16_0_ym19_1_1481131971764_13083">debug3: mm_request_send entering: type 22<br id="yui_3_16_0_ym19_1_1481131971764_13084">debug3: mm_key_allowed: waiting for MONITOR_ANS_KEYALLOWED [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13085">debug3: mm_request_receive_expect entering: type 22 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13086">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13087">debug2: userauth_pubkey: authenticated 0 pkalg ssh-rsa [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13088">Postponed publickey for a_aaaaaaa.aaaaa@xxxxxxx.xxxx from 10.10.10.10 port 45036 ssh2 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13089">debug1: userauth-request for user a_aaaaaaa.aaaaa@xxxxxxx.xxxx service ssh-connection method publickey [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13090">debug1: attempt 2 failures 0 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13091">debug2: input_userauth_request: try method publickey [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13092">debug3: mm_key_allowed entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13093">debug3: mm_request_send entering: type 21 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13094">debug3: mm_key_allowed: waiting for MONITOR_ANS_KEYALLOWED [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13095">debug3: mm_request_receive_expect entering: type 22 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13096">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13097">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13098">debug3: monitor_read: checking request 21<br id="yui_3_16_0_ym19_1_1481131971764_13099">debug3: mm_answer_keyallowed entering<br id="yui_3_16_0_ym19_1_1481131971764_13100">debug3: mm_answer_keyallowed: key_from_blob: 0x7fcb153143e0<br id="yui_3_16_0_ym19_1_1481131971764_13101">debug1: Checking blacklist file /usr/share/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_13102">debug1: Checking blacklist file /etc/ssh/blacklist.RSA-2048<br id="yui_3_16_0_ym19_1_1481131971764_13103">debug1: temporarily_use_uid: 1039812876/1039812876 (e=0/0)<br id="yui_3_16_0_ym19_1_1481131971764_13104">debug1: trying public key file /home/xxxxxxx.xxxx/a_aaaaaaa.aaaaa/.ssh/authorized_keys<br id="yui_3_16_0_ym19_1_1481131971764_13105">debug1: fd 8 clearing O_NONBLOCK<br id="yui_3_16_0_ym19_1_1481131971764_13106">debug1: matching key found: file /home/xxxxxxx.xxxx/a_aaaaaaa.aaaaa/.ssh/authorized_keys, line 8<br id="yui_3_16_0_ym19_1_1481131971764_13107">Found matching RSA key: a6:61:f3:d1:f6:87:4f:e2:27:49:88:f8:09:93:11:27<br id="yui_3_16_0_ym19_1_1481131971764_13108">debug1: restore_uid: 0/0<br id="yui_3_16_0_ym19_1_1481131971764_13109">debug3: mm_answer_keyallowed: key 0x7fcb153143e0 is allowed<br id="yui_3_16_0_ym19_1_1481131971764_13110">debug3: mm_request_send entering: type 22<br id="yui_3_16_0_ym19_1_1481131971764_13111">debug3: mm_key_verify entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13112">debug3: mm_request_send entering: type 23 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13113">debug3: mm_key_verify: waiting for MONITOR_ANS_KEYVERIFY [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13114">debug3: mm_request_receive_expect entering: type 24 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13115">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13116">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13117">debug3: monitor_read: checking request 23<br id="yui_3_16_0_ym19_1_1481131971764_13118">debug1: ssh_rsa_verify: signature correct<br id="yui_3_16_0_ym19_1_1481131971764_13119">debug3: mm_answer_keyverify: key 0x7fcb153143e0 signature verified<br id="yui_3_16_0_ym19_1_1481131971764_13120">debug3: mm_request_send entering: type 24<br id="yui_3_16_0_ym19_1_1481131971764_13121">debug3: mm_request_receive_expect entering: type 51<br id="yui_3_16_0_ym19_1_1481131971764_13122">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13123">debug1: do_pam_account: called<br id="yui_3_16_0_ym19_1_1481131971764_13124">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [be_get_account_info] (0x0100): Got request for [3][1][name=a_aaaaaaa.aaaaa]<br id="yui_3_16_0_ym19_1_1481131971764_13125">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [acctinfo_callback] (0x0100): Request processed. Returned 3,95,Account info lookup failed<br id="yui_3_16_0_ym19_1_1481131971764_13126">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [be_pam_handler] (0x0100): Got request with the following data<br id="yui_3_16_0_ym19_1_1481131971764_13127">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): command: PAM_ACCT_MGMT<br id="yui_3_16_0_ym19_1_1481131971764_13128">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): domain: xxxxxxx.xxxx<br id="yui_3_16_0_ym19_1_1481131971764_13129">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): user: a_aaaaaaa.aaaaa@xxxxxxx.xxxx<br id="yui_3_16_0_ym19_1_1481131971764_13130">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): service: sshd<br id="yui_3_16_0_ym19_1_1481131971764_13131">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): tty: ssh<br id="yui_3_16_0_ym19_1_1481131971764_13132">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): ruser:<br id="yui_3_16_0_ym19_1_1481131971764_13133">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): rhost: 10.10.10.10<br id="yui_3_16_0_ym19_1_1481131971764_13134">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): authtok type: 0<br id="yui_3_16_0_ym19_1_1481131971764_13135">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): newauthtok type: 0<br id="yui_3_16_0_ym19_1_1481131971764_13136">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): priv: 1<br id="yui_3_16_0_ym19_1_1481131971764_13137">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [pam_print_data] (0x0100): cli_pid: 1839<br id="yui_3_16_0_ym19_1_1481131971764_13138">(Wed Dec  7 17:31:47 2016) [sssd[be[freeipa.domain.com]]] [ipa_hostgroup_info_done] (0x0200): Dereferenced host group: servers<br id="yui_3_16_0_ym19_1_1481131971764_13139">(Wed Dec  7 17:31:48 2016) [sssd[be[freeipa.domain.com]]] [hbac_get_category] (0x0200): Category is set to 'all'.<br id="yui_3_16_0_ym19_1_1481131971764_13140">(Wed Dec  7 17:31:48 2016) [sssd[be[freeipa.domain.com]]] [ipa_hbac_evaluate_rules] (0x0080): Access denied by HBAC rules<br id="yui_3_16_0_ym19_1_1481131971764_13141">(Wed Dec  7 17:31:48 2016) [sssd[be[freeipa.domain.com]]] [be_pam_handler_callback] (0x0100): Backend returned: (0, 6, <NULL>) [Success]<br id="yui_3_16_0_ym19_1_1481131971764_13142">(Wed Dec  7 17:31:48 2016) [sssd[be[freeipa.domain.com]]] [be_pam_handler_callback] (0x0100): Sending result [6][xxxxxxx.xxxx]<br id="yui_3_16_0_ym19_1_1481131971764_13143"><br id="yui_3_16_0_ym19_1_1481131971764_13144">==> auth.log <==<br id="yui_3_16_0_ym19_1_1481131971764_13145">Dec  7 17:31:48 jamesprecise sshd[1839]: pam_sss(sshd:account): Access denied for user a_aaaaaaa.aaaaa@xxxxxxx.xxxx: 6 (Permission denied)<br id="yui_3_16_0_ym19_1_1481131971764_13146"><br id="yui_3_16_0_ym19_1_1481131971764_13147">==> sssd/sssd_freeipa.domain.com.log <==<br id="yui_3_16_0_ym19_1_1481131971764_13148">(Wed Dec  7 17:31:48 2016) [sssd[be[freeipa.domain.com]]] [be_pam_handler_callback] (0x0100): Sent result [6][xxxxxxx.xxxx]<br id="yui_3_16_0_ym19_1_1481131971764_13149">debug3: PAM: do_pam_account pam_acct_mgmt = 6 (Permission denied)<br id="yui_3_16_0_ym19_1_1481131971764_13150">debug3: mm_request_send entering: type 52<br id="yui_3_16_0_ym19_1_1481131971764_13151">Failed publickey for a_aaaaaaa.aaaaa@xxxxxxx.xxxx from 10.10.10.10 port 45036 ssh2<br id="yui_3_16_0_ym19_1_1481131971764_13152">debug2: userauth_pubkey: authenticated 1 pkalg ssh-rsa [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13153">debug3: mm_do_pam_account entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13154">debug3: mm_request_send entering: type 51 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13155">debug3: mm_request_receive_expect entering: type 52 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13156">debug3: mm_request_receive entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13157">debug3: mm_do_pam_account returning 0 [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13158">Access denied for user a_aaaaaaa.aaaaa@xxxxxxx.xxxx by PAM account configuration [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13159">debug1: do_cleanup [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13160">debug3: PAM: sshpam_thread_cleanup entering [preauth]<br id="yui_3_16_0_ym19_1_1481131971764_13161">debug1: monitor_read_log: child log fd closed<br id="yui_3_16_0_ym19_1_1481131971764_13162">debug3: mm_request_receive entering<br id="yui_3_16_0_ym19_1_1481131971764_13163">debug1: do_cleanup<br id="yui_3_16_0_ym19_1_1481131971764_13164">debug1: PAM: cleanup<br id="yui_3_16_0_ym19_1_1481131971764_13165">debug3: PAM: sshpam_thread_cleanup entering<br id="yui_3_16_0_ym19_1_1481131971764_13166">root@jamesprecise:/var/log# (Wed Dec  7 17:31:56 2016) [sssd[be[freeipa.domain.com]]] [sdap_id_conn_data_expire_handler] (0x0080): connection is about to expire, releasing it<br id="yui_3_16_0_ym19_1_1481131971764_13167">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [fo_resolve_service_send] (0x0100): Trying to resolve service 'IPA'<br id="yui_3_16_0_ym19_1_1481131971764_13168">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [be_resolve_server_process] (0x0200): Found address for server freeipa.server.com: [11.11.11.11] TTL 1177<br id="yui_3_16_0_ym19_1_1481131971764_13169">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [fo_resolve_service_send] (0x0100): Trying to resolve service 'IPA'<br id="yui_3_16_0_ym19_1_1481131971764_13170">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [be_resolve_server_process] (0x0200): Found address for server freeipa.server.com: [11.11.11.11] TTL 1177<br id="yui_3_16_0_ym19_1_1481131971764_13171"><br id="yui_3_16_0_ym19_1_1481131971764_13172">==> sssd/ldap_child.log <==<br id="yui_3_16_0_ym19_1_1481131971764_13173">(Wed Dec  7 17:32:04 2016) [[sssd[ldap_child[1841]]]] [ldap_child_get_tgt_sync] (0x0100): Principal name is: [host/client-freeipa.com@freeipa.domain.com]<br id="yui_3_16_0_ym19_1_1481131971764_13174">(Wed Dec  7 17:32:04 2016) [[sssd[ldap_child[1841]]]] [ldap_child_get_tgt_sync] (0x0100): Using keytab [default]<br id="yui_3_16_0_ym19_1_1481131971764_13175">(Wed Dec  7 17:32:04 2016) [[sssd[ldap_child[1841]]]] [ldap_child_get_tgt_sync] (0x0100): Will canonicalize principals<br id="yui_3_16_0_ym19_1_1481131971764_13176"><br id="yui_3_16_0_ym19_1_1481131971764_13177">==> syslog <==<br id="yui_3_16_0_ym19_1_1481131971764_13178">Dec  7 17:32:04 jamesprecise kernel: [ 5423.086166] type=1400 audit(1481131924.403:53): apparmor="ALLOWED" operation="open" parent=952 profile="/usr/sbin/sssd" name="/var/lib/sss/pubconf/krb5.include.d/" pid=1841 comm="ldap_child" requested_mask="r" denied_mask="r" fsuid=0 ouid=0<br id="yui_3_16_0_ym19_1_1481131971764_13179">Dec  7 17:32:04 jamesprecise kernel: [ 5423.086190] type=1400 audit(1481131924.403:54): apparmor="ALLOWED" operation="open" parent=952 profile="/usr/sbin/sssd" name="/var/lib/sss/pubconf/krb5.include.d/domain_realm_freeipa-realm" pid=1841 comm="ldap_child" requested_mask="r" denied_mask="r" fsuid=0 ouid=0<br id="yui_3_16_0_ym19_1_1481131971764_13180"><br id="yui_3_16_0_ym19_1_1481131971764_13181">==> sssd/sssd_freeipa.domain.com.log <==<br id="yui_3_16_0_ym19_1_1481131971764_13182">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [sdap_cli_auth_step] (0x0100): expire timeout is 900<br id="yui_3_16_0_ym19_1_1481131971764_13183">(Wed Dec  7 17:32:04 2016) [sssd[be[freeipa.domain.com]]] [sasl_bind_send] (0x0100): Executing sasl bind mech: GSSAPI, user: host/client-freeipa.com<br id="yui_3_16_0_ym19_1_1481131971764_13184">(Wed Dec  7 17:32:05 2016) [sssd[be[freeipa.domain.com]]] [child_sig_handler] (0x0100): child [1841] finished successfully.<br id="yui_3_16_0_ym19_1_1481131971764_13185">(Wed Dec  7 17:32:05 2016) [sssd[be[freeipa.domain.com]]] [fo_set_port_status] (0x0100): Marking port 0 of server 'freeipa.server.com' as 'working'<br id="yui_3_16_0_ym19_1_1481131971764_13186">(Wed Dec  7 17:32:05 2016) [sssd[be[freeipa.domain.com]]] [set_server_common_status] (0x0100): Marking server 'freeipa.server.com' as 'working'<br id="yui_3_16_0_ym19_1_1481131971764_13187">(Wed Dec  7 17:32:05 2016) [sssd[be[freeipa.domain.com]]] [sdap_sudo_set_usn] (0x0200): SUDO higher USN value: [572244]<br id="yui_3_16_0_ym19_1_1481131971764_13188"><br id="yui_3_16_0_ym19_1_1481131971764_13189"><br id="yui_3_16_0_ym19_1_1481131971764_13190"><br id="yui_3_16_0_ym19_1_1481131971764_13191"><br></div></body></html>