SSH Error - Permission denied (publickey,keyboard-interactive) | Unix Linux Forums | AIX

  Go Back    


AIX AIX is IBM's industry-leading UNIX operating system that meets the demands of applications that businesses rely upon in today's marketplace.

SSH Error - Permission denied (publickey,keyboard-interactive)

AIX


Tags
aix, unix

Closed Thread    
 
Thread Tools Search this Thread Display Modes
    #1  
Old 08-02-2011
nice_chapp nice_chapp is offline
Registered User
 
Join Date: Aug 2011
Last Activity: 23 May 2012, 11:24 AM EDT
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Network SSH Error - Permission denied (publickey,keyboard-interactive)

Hello,

I'm trying to setup password less authentication to remote ssh server. I generated the public key and gave it to the vendor and The key is added in the remote machines authorized_keys file.

When I try to connect to a remote machine through SFTP username@host I am getting the error message

Permission denied (publickey,password,keyboard-interactive).

Can any one tell me what is the problem.

Here is the debug log:


Code:
Connecting to sshftp-remoteserver.com...
OpenSSH_4.7p1, OpenSSL 0.9.8f 11 Oct 2007
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Failed dlopen: /usr/krb5/lib/libkrb5.a(libkrb5.a.so):   0509-022 Cannot load module /usr/krb5/lib/libkrb5.a(libkrb5.a.so).
        0509-026 System error: A file or directory in the path name does not exist.

debug1: Error loading Kerberos, disabling Kerberos auth.
debug1: Connecting to sshftp-remoteserver.com [xxx.xxx.xxx.xxx] port 22.
debug1: Connection established.
debug1: identity file /cgate/.ssh/id_rsa type 1
debug1: identity file /cgate/.ssh/id_dsa type -1
debug1: Remote protocol version 2.0, remote software version Connect:Enterprise_UNIX_2.4.02
debug1: no match: Connect:Enterprise_UNIX_2.4.02
debug1: Enabling compatibility mode for protocol 2.0
debug1: Local version string SSH-2.0-OpenSSH_4.7
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: server->client aes128-cbc hmac-sha1 none
debug1: kex: client->server aes128-cbc hmac-sha1 none
debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<2048<8192) sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP
debug1: SSH2_MSG_KEX_DH_GEX_INIT sent
debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY
debug1: Host 'sshftp-remoteserver.com' is known and matches the RSA host key.
debug1: Found key in /cgate/.ssh/known_hosts:13
debug1: ssh_rsa_verify: signature correct
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: SSH2_MSG_SERVICE_REQUEST sent
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: Next authentication method: publickey
debug1: Offering public key: /cgate/.ssh/id_rsa
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: Trying private key: /cgate/.ssh/id_dsa
debug1: Next authentication method: keyboard-interactive
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: No more authentication methods to try.
Permission denied (publickey,keyboard-interactive).
Connection closed

Thanks,
-raj

Last edited by pludi; 08-02-2011 at 02:41 PM..
Sponsored Links
    #2  
Old 08-02-2011
Corona688 Corona688 is offline Forum Staff  
Mead Rotor
 
Join Date: Aug 2005
Last Activity: 24 October 2014, 11:36 AM EDT
Location: Saskatchewan
Posts: 19,682
Thanks: 823
Thanked 3,352 Times in 3,139 Posts
Instead of giving it to the vendor, how about ssh-copy-id ?

If you don't have that level of control, you'll need to complain to your vendor.
Sponsored Links
    #3  
Old 08-03-2011
kah00na's Avatar
kah00na kah00na is offline
Registered User
 
Join Date: Jul 2007
Last Activity: 15 October 2014, 11:26 AM EDT
Location: Kansas
Posts: 298
Thanks: 21
Thanked 24 Times in 21 Posts
Chances are, the problem is on their side. They need to be sure that it was loaded to their authorized_keys file and that the permissions going down to the $HOME/.ssh directory are set restrictive enough. Also, they need to be sure that the $HOME/.ssh/authorized_keys file they placed your public key into is that of the user with which you are trying to connect. The public key authentication is failing though. You can see it here being attempted.

Code:
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: Next authentication method: publickey
debug1: Offering public key: /cgate/.ssh/id_rsa
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: Trying private key: /cgate/.ssh/id_dsa
debug1: Next authentication method: keyboard-interactive
debug1: Authentications that can continue: publickey,keyboard-interactive
debug1: No more authentication methods to try.

    #4  
Old 08-03-2011
ram1729 ram1729 is offline
Registered User
 
Join Date: May 2008
Last Activity: 27 September 2014, 6:17 AM EDT
Posts: 16
Thanks: 0
Thanked 1 Time in 1 Post
Do you have read permissions on authorized_keys at destination server ?

Also can you just check as is below output & it will show where to find authorized keys for a user.


<destinationserver>:/etc/ssh>grep AuthorizedKeysFile /etc/ssh/sshd_config
#AuthorizedKeysFile /etc/ssh/auth_keys/%u
AuthorizedKeysFile .ssh/authorized_keys
<destination server>:/etc/ssh>

Last edited by ram1729; 08-03-2011 at 04:54 PM..
Sponsored Links
    #5  
Old 08-17-2011
nice_chapp nice_chapp is offline
Registered User
 
Join Date: Aug 2011
Last Activity: 23 May 2012, 11:24 AM EDT
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Issue resolved

Thanks Guys, i'm able to resolve the issue. We asked the vendor for their Solaris logs - /var/adm/message , /var/adm/sshauthlog, /var/adm/authlog and then able to figure it out.

The user id they created is in all upper case, and we were using lower case..! I never heard a situation where the user name is case sensitive, esp. for an ftp server.... Even our unix admin is stumpted on it!
Sponsored Links
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Permission Denied Error with X11 Ricardo-san OS X (Apple) 2 02-02-2009 01:00 PM
ERROR : Permission denied (publickey,password,keyboard-interactive). deepusunil Shell Programming and Scripting 5 10-10-2008 01:43 PM
SSH permission denied (publickey) VRoemer UNIX for Dummies Questions & Answers 2 03-31-2008 11:45 PM
permission denied error Anji Shell Programming and Scripting 2 01-08-2008 05:34 AM
rm Permission Denied error Cech2002 UNIX for Dummies Questions & Answers 7 06-26-2002 06:24 PM



All times are GMT -4. The time now is 12:11 PM.