SSH pubkey authetication fails when GSSAPI enabled

Bug #2028282 reported by Moritz Carmesin
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
openssh (Ubuntu)
Triaged
High
Unassigned

Bug Description

Since the upgrade from Ubuntu 20.04 to 22.04 the SSH login via a SSH pubkey to our servers fails, while password and kerberos are still working.

$ssh user@server
sign_and_send_pubkey: internal error: initial hostkey not recorded

This seem related to the bugreport at openssh: https://bugzilla.mindrot.org/show_bug.cgi?id=3406

ProblemType: Bug
DistroRelease: Ubuntu 22.04
Package: openssh-server 1:8.9p1-3ubuntu0.1
ProcVersionSignature: Ubuntu 5.15.0-76.83-generic 5.15.99
Uname: Linux 5.15.0-76-generic x86_64
ApportVersion: 2.20.11-0ubuntu82.5
Architecture: amd64
CasperMD5CheckResult: pass
CloudArchitecture: x86_64
CloudID: none
CloudName: none
CloudPlatform: none
CloudSubPlatform: config
Date: Thu Jul 20 17:25:01 2023
InstallationDate: Installed on 2020-08-24 (1060 days ago)
InstallationMedia: Ubuntu-Server 20.04.1 LTS "Focal Fossa" - Release amd64 (20200731)
SourcePackage: openssh
UpgradeStatus: Upgraded to jammy on 2023-07-20 (0 days ago)

Revision history for this message
Moritz Carmesin (carmesinus) wrote :
Revision history for this message
Steve Langasek (vorlon) wrote :

I can confirm this behavior here.

I've found I can work around it by unsetting KRB5CCNAME in the client environment.

Changed in openssh (Ubuntu):
importance: Undecided → High
status: New → Triaged
Revision history for this message
Moritz Carmesin (carmesinus) wrote :

Unsetting KRB5CCNAME breaks the Kerbreros based login, so it is really just an emergency workaround.

Revision history for this message
Steve Langasek (vorlon) wrote : Re: [Bug 2028282] Re: SSH pubkey authetication fails when GSSAPI enabled

On Wed, Jul 26, 2023 at 07:24:37AM -0000, Moritz Carmesin wrote:
> Unsetting KRB5CCNAME breaks the Kerbreros based login, so it is really
> just an emergency workaround.

You can unset it for just the ssh process that needs non-Kerberos login.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.