Koozali.org: home of the SME Server

Very strange

Offline Normando

  • *
  • 841
  • +2/-1
    • Unixlan
Very strange
« on: April 24, 2006, 04:04:53 PM »
Very strange
Today to the morning I connect to my server (located in another city) via putty, and for my surprise it requests to me to keep the key in the registry. It was very rare, I never modifies SSH keys of the SME. After accepting to keep it permanently, see this message:

Welcome to SME Server 6.0.1-01
No mail.

What is that?
Looking for strings (No mail.) within archives, I found it into /sbin/sshd line 1648 after /etc/motd.

Lookin into log I found this:
Quote
Apr 24 02:03:25 servidor-digital oidentd[10915]: Connection from www.francecreation.com (62.129.1$
Apr 24 02:03:25 servidor-digital oidentd[10915]: [www.francecreation.com] Successful lookup: 4013$
Apr 24 06:05:24 servidor-digital sshd[20265]: Did not receive identification string from 172.177.$
Apr 24 06:08:57 servidor-digital sshd2[20468]: Listener created on port 22.
Apr 24 06:08:57 servidor-digital sshd2[20476]: Daemon is running.
Apr 24 06:09:36 servidor-digital sshd[20480]: Listener created on port 11111.
Apr 24 06:09:36 servidor-digital sshd[20488]: Daemon is running.
Apr 24 06:10:41 servidor-digital sshd[20544]: Listener created on port 11111.
Apr 24 06:10:41 servidor-digital sshd[20552]: Daemon is running.
Apr 24 06:10:45 servidor-digital sshd[20553]: DNS lookup failed for "216.187.103.251".

I don't know if this is rare, but I have configurated SSH with port 11111.

Is there a way to regenerate a new ssh key automaticaly each year?

I do not understand anything

Thanks for help.

Normando

Offline Normando

  • *
  • 841
  • +2/-1
    • Unixlan
Very strange
« Reply #1 on: April 25, 2006, 04:53:17 AM »
Another server too!!
I founs ssh key has stored for putty in my workstation, and see now store as "dss" keys instead of "rsa2" keys.

Whats happens???
Now I login with putty through dss keys???
Please, help me, I don't know if this issue is a security hole.
I repeat, in two servers I have the same issue today.
Normando

Offline kruhm

  • *
  • 680
  • +0/-0
Very strange
« Reply #2 on: April 30, 2006, 08:25:07 AM »
its probably your putty not the servers. you may have accidentally changed some putty settings.

Offline Normando

  • *
  • 841
  • +2/-1
    • Unixlan
Very strange
« Reply #3 on: April 30, 2006, 08:52:10 AM »
Thanks for the reply kruhm, but I have the same issue. I try to conect with other workstation and other putty, and I have the same string "No Mail".

Offline kruhm

  • *
  • 680
  • +0/-0
Very strange
« Reply #4 on: April 30, 2006, 07:30:13 PM »
#did you check out your /etc/motd file?
cat /etc/motd

#this stands for Message Of The Day. It could be in there. If so, just erase it or put in whatever you want.

Offline Normando

  • *
  • 841
  • +2/-1
    • Unixlan
Very strange
« Reply #5 on: April 30, 2006, 10:50:19 PM »
Yes, modt is at /etc/ directory. But my problem is'nt modt. The problem is the string "No Mail" after modt, and the automatic change of RSA2 keys to DSS.
I don't know why when I logged always show motd, but a few days ago the string "No Mail" is put after modt and I need again to accept the DSS key to cache for putty, I not modifie any key in the server.

Sorry for my bad english
Thank you