delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2004/09/16/14:18:01

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Date: Thu, 16 Sep 2004 22:17:36 +0400
From: Konstantin Andreev <kostya AT tortrade DOT ru>
Organization: TOR Company
Message-ID: <179199034656.20040916221736@tortrade.ru>
To: cygwin AT cygwin DOT com
Subject: OpenSSH privilege separation fails: connections starts to be dropped.
Mime-Version: 1.0

In the first place, OpenSSH daemon works fine for me, if
"UsePrivilegeSeparation" feature is disabled.

I enabled "UsePrivilegeSeparation" and properly configured my system
for use of this feature: set up account "sshd" and set up permissions
for /var/empty.

In this configuration OpenSSH daemon starts without complains, but
drops incoming connections immediately after connect.

The appropriate debug output of SSH daemon (debug level 3) is:

------------------- cut here --------------------------------
...
debug2: Network child is on pid 1000
debug3: privsep user:group 1004:100ed
debug1: permanently_set_uid: 1004/100
permanently_set_uid: was able to restore old [e]gid
------------------- cut here --------------------------------

The last line has severity "fatal", and is sent to Event Log.

My setup is:

   cygwin-1.5.11-1, openssh-3.9p1-1
   @ Windows XP Professinal RUS SP2

   SSH daemon is running under (NT AUTHORITY/SYSTEM) account.
   /var/empty resides on NTFS, permissions set appropriately,
   and test "sshd -t" does not complain about anything.

   
There was a discussion recently in this maillist with very close
topic:
  "SSH on Cygwin Immediate Drops Connections"
  (http://sources.redhat.com/ml/cygwin/2004-09/msg00298.html)


But that topic is not applicable, because addresses another problem:

>> debug1: permanently_set_uid: 1107/513
>> setreuid 1107: Permission denied


What could I do to cope with SSH daemon failures ?

-- -
TOR Trade Company, IT Department,
Konstantin Andreev.



--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019