cant login with ltsp after update of openssh/openssl

Bug #230565 reported by Lance Russell
12
Affects Status Importance Assigned to Milestone
ldm (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

The recent update to correct the OpenSSL/OpenSSH/OpenVPN vulnerability rebuilds the server keys. However, if EdUbuntu is installed, the keys should be copied over to the chroot. The chroot image must then be updated.

See https://wiki.edubuntu.org/DebugThinClientLogin for the steps that must be taken.

This occurs with 8.04 but most likely affects all versions. 7.10 and up require the image update.

Revision history for this message
Stéphane Graber (stgraber) wrote :

It's the normal behavior after the openssh update, I don't think there was an easy way to trigger an ltsp-update-sshkeys + ltsp-update-image from the openssh upgrade process.

Instructions on how to update the ssh keys in the chroot have been posted to the edubuntu-users mailing-list : https://lists.ubuntu.com/archives/edubuntu-users/2008-May/004052.html

Revision history for this message
Oliver Grawert (ogra) wrote :

this is expected beahvior and not a bug, i agree that the info in here is essential though and the bug should be converted to a question

Changed in ltsp:
status: New → Invalid
Revision history for this message
Florian Hars (hars) wrote :

There is at least a wishlist bug hiding in there, in so far as ldm should give a meaningful error message if there are host key problems, instead of hanging indefinitely and lying to the user about what it does.

Changed in ltsp:
status: Invalid → New
Revision history for this message
Oliver Grawert (ogra) wrote :

ldm usually says "This workstation is not authorized to connect to server" on key problems, if that was not the case for you it is indeed a bug, can you confirm the message was not shown ?

Revision history for this message
Florian Hars (hars) wrote :

It was definitely hanging in "Trying to verify password..."

Revision history for this message
Daniel Barlow (dan-telent) wrote :

It would be a help if the message on openssh upgrade warned, for example, that "some clients (e.g. openssh and LTSP) will warn or fail to connect after this upgrade, until their cached host keys are updated or removed"

This would be a whole lot more useful as a heads-up than the "if you don't understand this message you can ignore it" line presently used.

Revision history for this message
Scott Balneaves (sbalneav) wrote :

I think this one can simply be handled with a documentation update. I'll see about adding it to the docs package.

Changed in ldm:
status: New → Confirmed
Revision history for this message
Stéphane Graber (stgraber) wrote :

ltsp-update-sshkeys is now in the documentation.

Changed in ldm (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.