Comment 19 for bug 2053146

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Jammy verification

In all architectures (except i386, which is a known failure everywhere) the new ssh-gssapi test passed.

Here is the run on amd64[1]:
3438s autopkgtest [16:33:21]: test ssh-gssapi: [-----------------------
3438s ## Setting up test environment
3438s ## Creating Kerberos realm EXAMPLE.FAKE
3438s Loading random data
3438s Initializing database '/var/lib/krb5kdc/principal' for realm 'EXAMPLE.FAKE',
3438s master key name '<email address hidden>'
3438s ## Creating principals
3438s Authenticating as principal <email address hidden> with password.
3438s Principal "<email address hidden>" created.
3438s Authenticating as principal <email address hidden> with password.
3438s Principal "<email address hidden>" created.
3438s ## Extracting service principal host/sshd-gssapi.example.fake
3438s Authenticating as principal <email address hidden> with password.
3438s Entry for principal host/sshd-gssapi.example.fake with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
3438s Entry for principal host/sshd-gssapi.example.fake with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab.
3438s ## Adjusting /etc/krb5.conf
3438s ## TESTS
3438s
3438s ## TEST test_gssapi_login
3438s ## Configuring sshd for gssapi-with-mic authentication
3438s ## Restarting ssh
3438s ## Obtaining TGT
3438s Password for <email address hidden>:
3438s Ticket cache: FILE:/tmp/krb5cc_0
3438s Default principal: <email address hidden>
3438s
3438s Valid starting Expires Service principal
3438s 04/05/24 16:33:20 04/06/24 02:33:20 <email address hidden>
3438s renew until 04/06/24 16:33:20
3438s
3438s ## ssh'ing into localhost using gssapi-with-mic auth
3438s Warning: Permanently added 'sshd-gssapi.example.fake' (ED25519) to the list of known hosts.
3439s Fri Apr 5 16:33:21 UTC 2024
3439s
3439s ## checking that we got a service ticket for ssh (host/)
3439s 04/05/24 16:33:21 04/06/24 02:33:20 host/sshd-gssapi.example.fake@
3439s Ticket server: <email address hidden>
3439s
3439s ## Checking ssh logs to confirm gssapi-with-mic auth was used
3439s Apr 05 16:33:21 sshd-gssapi.example.fake sshd[1518]: Accepted gssapi-with-mic for testuser1457 from 127.0.0.1 port 50668 ssh2: <email address hidden>
3439s ## PASS test_gssapi_login
3439s
3439s ## TEST test_gssapi_keyex_login
3439s ## Configuring sshd for gssapi-keyex authentication
3439s ## Restarting ssh
3439s ## Obtaining TGT
3439s Password for <email address hidden>:
3439s Ticket cache: FILE:/tmp/krb5cc_0
3439s Default principal: <email address hidden>
3439s
3439s Valid starting Expires Service principal
3439s 04/05/24 16:33:21 04/06/24 02:33:21 <email address hidden>
3439s renew until 04/06/24 16:33:21
3439s
3439s ## ssh'ing into localhost using gssapi-keyex auth
3439s Fri Apr 5 16:33:21 UTC 2024
3439s
3439s ## checking that we got a service ticket for ssh (host/)
3439s 04/05/24 16:33:21 04/06/24 02:33:21 host/sshd-gssapi.example.fake@
3439s Ticket server: <email address hidden>
3439s
3439s ## Checking ssh logs to confirm gssapi-keyex auth was used
3439s Apr 05 16:33:21 sshd-gssapi.example.fake sshd[1558]: Accepted gssapi-keyex for testuser1457 from 127.0.0.1 port 50670 ssh2: <email address hidden>
3439s ## PASS test_gssapi_keyex_login
3439s
3439s ## ALL TESTS PASSED
3439s ## Cleaning up
3439s autopkgtest [16:33:22]: test ssh-gssapi: -----------------------]
3439s autopkgtest [16:33:22]: test ssh-gssapi: - - - - - - - - - - results - - - - - - - - - -
3439s ssh-gssapi PASS
3440s autopkgtest [16:33:23]: @@@@@@@@@@@@@@@@@@@@ summary
3440s regress PASS
3440s ssh-gssapi PASS

Jammy verification succeeded.

1. https://autopkgtest.ubuntu.com/results/autopkgtest-jammy/jammy/amd64/o/openssh/20240405_163345_c46fa@/log.gz