when I do ping to newly created zone it showing alive, I am able to login through zone console zlogin -C -E <zone name>
I created a test account on zone which is already existing under global zone and try to ssh, it is working fine but my problem is with root user, when i am doing ssh root@<zonename> it is showing below error
Could some one please help in fixing this issue.
Thanks,
Alberto
Last edited by DukeNuke2; 08-03-2009 at 07:59 AM..
Reason: added code tags
okay people i need some help:
i was able to configure zones on my solaris 10 server, the problem is I can't ssh into the zones!!! I can zlogin -C zone2 successfully for both zones. Am I missing something? I can ping the zones, but can't ssh. From the zones, I can ping my global server. (7 Replies)
Hi All,
I am getting zone error
# /usr/sbin/zoneadm -z asflxpoc1 boot -s
could not verify net address=169.185.246.229 physical=ce0: No such device or address
could not verify net address=169.185.246.230 physical=ce0: No such device or address
Any ideas for this error message.
The... (13 Replies)
Hello All,
I have a list of Local Zones in my list. I want to find out their Global Zone names exactly....I know the command "arp ..."But I dont know how to filter it correctly and find it out.
Thanks in advance,
Jacky (9 Replies)
I have a Solaris 10 box configured with a global zone and 3 non-global zones. All of the zones need to be configured so they can access and run an application in the global zone located at /export/home. How do i make this application and all of its accompanying files available to the 3 non-global... (3 Replies)
Hi Every,
I would like to know some questions on Zones???
1.what are types of zones we can install in global zone???
2.Exact difference between sparce root and whole root???
3.can we change the ip address of a running zone???
4.how to find our in which zone we are running and how many... (8 Replies)
Hi,
I use a zoned solaris box, 5.10 Generic_118833-33, E2900. It is used for both a database and application. The databases are installated on one zone and then there are separate live, development and test application zones.
There has been a requirement to install openldap on the... (1 Reply)
Hi Guys,
I haven't worked on solaris zones earlier. I have a query regarding the zones.
We have MQ software installed on a solaris container. I am not sure on which zone this s/w is intalled.
I have logged into this container via putty.
When I search for the package, I got the package... (7 Replies)
Hi friends,
Actually I faced problem in solaris zone. i was created 4 zones on my server. but one of them is not working ?
so, where i wll get the error logs, and how to troubleshoot the problem.
i have some kind of urgency.
Please reply. (2 Replies)
Hi guys and gals,
Does anyone know how to import solaris zones from the xml files that sit in /etc/zones?
I want the zones from one machine to another, all I have is the XML files for the zones, so I can't export them first.
Thanks in advance
Martin (1 Reply)
Hi All
Kindly let me know how can I move Solaris 10 OS running update 10 on physical machine to another machine solaris zone running Solaris 10 update 11 (2 Replies)
Discussion started by: amity
2 Replies
LEARN ABOUT OSF1
ssh-keysign
ssh-keysign(1M)ssh-keysign(1M)NAME
ssh-keysign - ssh helper program for host-based authentication
SYNOPSIS
ssh-keysign
ssh-keysign is used by ssh(1) to access the local host keys and generate the digital signature required during host-based authentication
with SSH protocol version 2. This signature is of data that includes, among other items, the name of the client host and the name of the
client user.
ssh-keysign is disabled by default and can be enabled only in the global client configuration file /etc/ssh/ssh_config by setting Host-
basedAuthentication to yes.
ssh-keysign is not intended to be invoked by the user, but from ssh. See ssh(1) and sshd(1M) for more information about host-based authen-
tication.
/etc/ssh/ssh_config
Controls whether ssh-keysign is enabled.
/etc/ssh/ssh_host_dsa_key
/etc/ssh/ssh_host_rsa_key
These files contain the private parts of the host keys used to generate the digital signature. They should be owned by root, readable
only by root, and not accessible to others. Because they are readable only by root, ssh-keysign must be set-uid root if host-based
authentication is used.
ssh-keysign will not sign host-based authentication data under the following conditions:
o If the HostbasedAuthentication client configuration parameter is not set to yes in /etc/ssh/ssh_config. This setting cannot be overri-
den in users' ~/.ssh/ssh_config files.
o If the client hostname and username in /etc/ssh/ssh_config do not match the canonical hostname of the client where ssh-keysign is
invoked and the name of the user invoking ssh-keysign.
In spite of ssh-keysign's restrictions on the contents of the host-based authentication data, there remains the ability of users to use it
as an avenue for obtaining the client's private host keys. For this reason host-based authentication is turned off by default.
See attributes(5) for descriptions of the following attributes:
+-----------------------------+-----------------------------+
| ATTRIBUTE TYPE | ATTRIBUTE VALUE |
+-----------------------------+-----------------------------+
|Availability |SUNWsshu |
+-----------------------------+-----------------------------+
|Interface Stability |Evolving |
+-----------------------------+-----------------------------+
ssh(1), sshd(1M), ssh_config(4), attributes(5)AUTHORS
Markus Friedl, markus@openbsd.org
HISTORY
ssh-keysign first appeared in Ox 3.2.
9 Jun 2004 ssh-keysign(1M)