Host fingerprint always changing, possibly dns resolve problem?

Hello,
I have a server that i try to connect which key fingerprint changes form time to time, and it stops me to connect (i get wrong password disconnect, although i am using an RSA key). Since its a physical machine lets exclude the part of any traffic shaping by the VPS provider. Also normally when i cant connect i cant see anything on the sshd logs of the machine. So this probably is a dns resolve problem ? Any recommendation or  knowledge that you can share with me to help me solve this problem ?

presumbly the previous stats were from the test socket as new stats are just the same
any exchnage problems  http://usertools.plus.net/exchanges/mso.php
http://usertools.plus.net/exchanges/?
http://btbusiness.custhelp.com/app/service_status
http://bt.custhelp.com/app/answers/detail/a_id/15036
http://community.plus.net/exchange-information/
If you like a post, or want to say thanks for a helpful answer, please click on the Ratings star on the left-hand side of the post.
If someone answers your question correctly please let other members know by clicking on ’Mark as Accepted Solution’.

Similar Messages

  • Possible DNS caching problem

    I just upgraded to Lion. I am a web deveoper and I just changed the DNS settings for a new website. While everyone else in my office is seeing the new wesite at the domain, I am stuck seeing the old. I have tried the DNS cache flushing techniques below (in addition to restarting, clearing cache, etc), but none have helped:
    sudo killall -HUP mDNSResponder
    dscachutil -flushcache
    In the terminal 'host domain.com' still points to the old server too.
    Seems like OSX is holding on to the old DNS settings. Any ideas?

    Select  ▹ System Preferences ▹ Network ▹ Advanced ▹ Proxies. If any boxes are checked, uncheck them, apply your changes, and try again.  You must apply the changes before they take effect.

  • VCSE DNS resolve problem

    Background:
    VCSC and VCSE are using same dns domain name
    e.g. VCSC.ipt.example.com
            VCSE.ipt.example.com
    SIP domain name : example.com
    When a internet VC endpoint call  a internal endpoint which is registered to VCSC, dial string is [email protected] ( both  SIP and H.323)
    Problem:
    vcsc and vcse are using same DNS servers. All dns servers are assigned public ip addresses.
    Since last week, VCSE cannot resolve any public domain name. It can only resolve vcse.ipt.example.com and vcsc.ipt.example.com
    But VCSC can resolve internet domain name like cisco.com
    VCSE can ping  internet ip address like 8.8.8.8 (google dns)
    Both VCSE and VCSC could resolve public domain name a week ago. The only changes to both VCSC and VCSE were  just search rules and transforms. Both of these rules should not affect the domain name resolution.
    Because VCSE cannot resolve public domain name, sip uri dialing  and enum dialing to internet endpoints fail due to resolution issue.
    Are there any other settings on VCSE except dns server ip addresses  can lead to resolution problem?
    Thanks

    Your question would be better off in the TelePresence section of the forums, where these devices are more actively discussed and people can help get you the answers you need.  You can move your question to the correct section by editing it and changing the categories at the bottom.
    Have you tried to revert the changes you made and see if DNS starts working again?

  • DNS resolve problem

    Dear All,
    I have setup a Primary DNS zone on mac os server 10.6.3 server for testing name bolt.com but when I ping it. It's showing me error ping:  cannot resolve the bolt.com: unknown host. I don't know what I have done mistake. I setup up the DNS on mac first time that's why I have not configure it properly please guys help me to enter the mac os x server world.
    Regards,
    Khalid

    You probably don't realize it, but just did the same thing.  You're again using a domain that you do not have registered.  You don't have example.com registered.  Please read the article I linked to.  (If something in that article doesn't make sense, please ask.)  Either use a completely bogus domain (and that's tougher to construct, if you don't know the DNS domain name formatting rules and how the names are assembled) or (better, easier, safer) get yourself a real and registered domain.
    I generally don't use the command line for setting up DNS, I prefer to use Server Admin.  Which is what is described in the linked article.  I'd let Server Admin guide you to a working configuration.
    If you do decide to manage DNS manually, you probably won't be able to use Server Admin in the future. 
    If you want to follow the command-line path for managing DNS, then please read the available ISC BIND9 documentation or (better) get yourself a copy of Cricket Liu's DNS and BIND book and start reading.  The fifth edition of the book was current, when last I looked.
    DNS works because folks follow a set of shared practices and guidelines. Not because folks might pick domains or IP address spaces in an uncoordinated fashion.  DNS server configuration errors and IP routing errors are among the very few things that one Internet site can do that can screw up access or routing for other Internet sites, too.  Hopefully your ISP will have limited the damage you can cause here, though.
    If you don't have access to a subdomain of a domain that you have registered or have permission to use, and strictly so you don't have to spend a few currency-units to register a test domain, then..   If you want a completely bogus domain name to test with, then something like myhost.test.khalidinzi is probably safe.  test.khalidinzi is your bogus domain, and myhost is a host name within that domain.

  • I can't connect to the itunes store and have some problems with other websites. Some websites load OK. I had the same problem on my iPad and changed the DNS, but don't want to do this on my iMac, anyway, surely I should have my router's DNS?

    I can't connect to the iTunes store from my iMac and have problems loading a number of other websites, however some websites load perfectly well. I have had the iTunes store issue on my iPad and resolved it by changing the DNS but surely I should use the DNS for my router. I don't really want to change it for the iMac as I access secure sites with it to internet shop.
    Any ideas, I was going to try loading Chrome but can't get it without going through the iTunes store. Anyway, that is treating the symprom not the cause.

    Adding Open DNS codes to your Network Preferences, should give good results in terms of speed-up as well as added security, (including anti-phishing and redirects) (Full information about Open DNS is here: http://www.opendns.com/home/nobloat ) and further independent information can be read here:
    http://reviews.cnet.com/8301-13727_7-57338784-263/free-dnscrypt-tool-enhances-ma c-web-security/?tag=mncol;txt
    and here:
    http://www.macworld.com/article/1146064/troubleshootdns.html?t=234
    Open System Preferences/Network. Double click on your connection type, or select it in the drop-down menu, and in the box marked 'DNS Servers' add the following two numbers:
    208.67.222.222
    208.67.220.220
    (You can also enter them if you click on Advanced and then DNS)
    Sometimes reversing the order of the DNS numbers can be beneficial in cases where there is a long delay before web pages start to load, and then suddenly load at normal speed:
    http://support.apple.com/kb/TS2296

  • Can't access some websites. Possibly DNS problem.

    This problem only started to occur a couple of days ago. I found that I can't access certain websites,but all the other computers in exactly the same network environment have no problem accessing them. I tried changing my DNS server settings from the servers my ISP provided to the Google DNSs, 8.8.8.8 and 4.4.4.4, and those websites I couldn't access before became accessible immediately, but some other websites, which I was able to access with the DNS provided by my ISP before, became inaccessible again. I tried using another set of DNS addresses, the same thing happened: some websites that I couldn't access before became accessible, but some others become inaccessible again. All these DNS servers that I used work perfectly on other computers in my network, so it has to be the problem of my computer. This has nothing to do with the browser, as all of the browers in my system have the same problem, even including the Internet Explorer in my VMware Windows virtual machine. I tried flushing the DNS cache with dscacheutil -flushcache, and it didn't work.
    I'm using Lion 10.7.3 on MacBook Pro MC371. Please help!

    Please give an example of a site you can't access now.

  • I used to have a podcast that had been accepted on Itunes, but my I began to have problems with my host, so I changed host and created a new podcast, and I submitted my new podcast, Apple refused, and now says the feed has already been submitted??

    I used to have a podcast that had been accepted on Itunes, but my I began to have problems with my host, so I changed host and created a new podcast, and I submitted my new podcast, Apple refused, and now says the feed has already been submitted? Maybe Itunes thought that I was someone trying to copy my old podcast because I kept the same name, I tried to change the names but it looks like I'm on a blocked list...

    There is a procedure for changing the feed URL for a podcast, which it seems you haven't followed: you have to add a special tag to the old feed - just submitting a new feed will have exactly the effect you describe. The proper method is described here:
    http://www.wilmut.webspace.virginmedia.com/notes/podcast.html#move

  • I got the ipad mini wi-fi version. Recently I've passed on ios7.02 and now my normal access to wi-fi became a great problem. Is any possibility to resolve this problem?

    I got the ipad mini wi-fi version. Recently I've passed on ios7.02 and now my normal access to wi-fi became a great problem. Is any possibility to resolve this problem?

    Hello bettyf25
    There could be a few things that could cause that issue. One is to make sure that the router settings are set to the recommended settings. The other is to go through the troubleshooting steps lied out in the articles below. This should give you a good starting point to get the issue resolved.
    iOS and OS X: Recommended settings for Wi-Fi routers and access points
    http://support.apple.com/kb/HT4199
    iOS: Troubleshooting Wi-Fi networks and connections
    http://support.apple.com/kb/TS1398
    Thanks for using Apple Support Communities.
    Regards,
    -Norm G.

  • Setting always changes by itself in my iPhone 5s, also every few calls I have to face a problem with a call without sound

    Setting always changes by itself in my iPhone 5s, also every few calls I have to face a problem with a call without sound, battery becomes empty quickly

    User troubleshooting steps as outlined in the manual are reset, restore, restore as new. Have you tried any of these?

  • [SOLVED] openssl: REMOTE HOST IDENTIFICATION HAS CHANGED! Hacked?

    There's a bit of Windowsisms in here, but one of the main questions is about openssl. As well, this post could help others regardless of the OS involved.
    I remote into a Windows 7 workstation at my work using xfreerdp going through Server 2008 R2. RDP is closed at the firewall to all but two IP addresses and neither of those uses port 3389. I'm connecting through NTLM for authentication then the connection is encrypted using TLS. FreeRDP uses openssl to handle SSL/TLS connections.
    Last week I remoted in my workstation first thing in the morning as I always do with no problems. I went to work that day and everything was normal. Later that night I went to remote in again and I got the "WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!" message. I followed the advice in the message and contacted the system admin:
    me wrote:skottish, were there any major changes in the system that could cause the RSA fingerprint to change?
    skottish wrote:I don't think so skottish. There were no changes made to the system beyond a simple update to the server's spam filters.
    There was nothing major that changed on the server and I wasn't anywhere in the system that could have forced a change. The only server-side work that I did was with some accounts in Active Directory and updated Exchange's spam filters.
    The way that I see it, and I may be missing something, is that there are four possibilities:
    1) A MITM attack. If this is the case then it was successful and I haven't tracked it down yet
    2) Someone accidentally changed something in the server
    3) Someone intentionally changed something in the server
    4) The server made it's own changes (which sadly wouldn't be out of character for a MS server)
    We do have an outside partner that has server access, but they told me that they weren't in there and I see no evidence to the contrary.
    My first question is am I missing any other possibilities?
    The second is how does openssl generate the RSA fingerprint of a computer? I've read many, many pages and so far I'm not finding any answers. If I could verify the fingerprint manually, that would help.
    The third is that if it is a MITM attack, what are the appropriate steps to identify it? I went through all of the ARP tables on the server and the workstation looking to see if anything is out of line and everything looks fine. I could run a capture off of our firewall and see if there's anything there, but I don't know Wireshark all that well, so I'm not sure what I would be looking for exactly.
    Thoughts?
    Last edited by skottish (2012-09-22 03:10:22)

    litemotiv wrote:Something like this happened to me before and it was caused by an unforeseen clock/time change, is that somehow possible in your case?
    Well, there was a clock change on my end that same day. For some reason openntpd was running about two minutes behind and it had been since I migrated to systemd. I switched to ntpd in order to correct it. I can't imagine why a change on the client side would make a difference though. But, I'm open to the possibility.
    --EDIT--
    I tried some experiments with openntpd, ntp, and changing clocks and such, but I couldn't trigger the error. I'm still open to the possibility though.
    -- RESOLUTION EDIT --
    It's not worth bumping this thread over the resolution of this, but someone may be interested in what happened for their own reference later.
    I realized that I was looking in the wrong direction and discovered that Windows automatically changed security keys for reasons that I don't understand yet. openssl did it's job perfectly. There was a force that wasn't the system administrator that made changes to the security of the system on a machine that hadn't changed physically. Is it possible that there has been an attack still? Yes, it's just much more unlikely now.
    Last edited by skottish (2012-09-22 03:25:31)

  • DNS Resolver not working with JDK 1.5.0_6 and Windows 2003

    I have a Windows Server 2003 machine which now has Java JDK 1.5.0_6 installed on it. Somehow the DNS resolver doesn't work - every call to InetAddress.getByName("host") throws an UnknownHostException. I've tried de-installed java and re-installing, but the problem remains. No traffic seems to be generated (i.e. no packets to port 53) when getByName() is called. I don't have any kind of firewall on the Windows Server 2003 machine.
    Has anyone ever seen this kind of behaviour / problem before and know of a solution?
    Thanks,
    Peter

    Ok, I finally managed to solve this problem. What was happening was that IPv6 was installed on this computer, and as a result Java was trying to do a DNS lookup using a IPv6 socket and failing. With the help of TracePlus Winsock, I discovered that internall Java's InetAddress.getByName does this:
    WSAStartup
    socket(INET6)
    getaddrinfo
    WSACleanup
    Two solutions are possible - either set the system preference java.net.preferIPv4Stack to true, or uninstall the IPv6 stack. Since I couldn't find a way to set the system preference in a persistent manner (apart from passing in an argument on the java command line), I uninstalled the IPv6 stack.
    Hope this helps someone else.
    Peter

  • DNS resolution problem

    I'm new at Solaris, so this is probably going to be a boneheaded question, but how do I configure Sol 10 x86 to point to a nameserver? My Solaris machine is on a private network (its IP adx is 192.168.0.4), and it uses a Win2k internet connection share at 192.168.0.1 for routing to the outside world. The Win2k box gets its IP adx from my ISP's DHCP server. There is no domain name for my little private network. I added all four hosts on my network to /etc/hosts, and I can ssh among them without any problems. I want to use my ISP's DNS server, and I've added its IP to the Solaris box /etc/resolv.conf. I can ping IPs on the outside (including the dns server), and nslookups and digs work fine, but I can't ping, say, google.com. Behold:
    [jcliburn@petrel ~]$ ssh kite
    Password:
    Last login: Wed Dec 29 19:55:59 2004
    Sun Microsystems Inc. SunOS 5.10 s10_72 December 2004
    $ ping google.com
    ping: unknown host google.com
    $ dig google.com
    ; <<>> DiG 8.4 <<>> google.com
    ;; res options: init recurs defnam dnsrch
    ;; got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56938
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 4, ADDITIONAL: 4
    ;; QUERY SECTION:
    ;; google.com, type = A, class = IN
    ;; ANSWER SECTION:
    google.com. 5M IN A 216.239.57.99
    google.com. 5M IN A 216.239.39.99
    google.com. 5M IN A 216.239.37.99
    ;; AUTHORITY SECTION:
    google.com. 1d6h25m34s IN NS ns1.google.com.
    google.com. 1d6h25m34s IN NS ns2.google.com.
    google.com. 1d6h25m34s IN NS ns3.google.com.
    google.com. 1d6h25m34s IN NS ns4.google.com.
    ;; ADDITIONAL SECTION:
    ns1.google.com. 1d6h33m54s IN A 216.239.32.10
    ns2.google.com. 1d6h33m54s IN A 216.239.34.10
    ns3.google.com. 1d6h33m54s IN A 216.239.36.10
    ns4.google.com. 1d6h33m54s IN A 216.239.38.10
    ;; Total query time: 431 msec
    ;; FROM: kite to SERVER: 205.152.137.252
    ;; WHEN: Wed Dec 29 20:21:16 2004
    ;; MSG SIZE sent: 28 rcvd: 222
    $ /usr/sfw/sbin/nslookup google.com
    Server: 205.152.137.252
    Address: 205.152.137.252#53
    Non-authoritative answer:
    Name: google.com
    Address: 216.239.37.99
    Name: google.com
    Address: 216.239.57.99
    Name: google.com
    Address: 216.239.39.99
    What am I doing wrong?

    Did some digging... Had to make a change in /etc/nsswitch.conf by adding "dns" to the hosts switch.
    Changed line FROM
    hosts: files
    TO
    hosts: dns files
    Names are resolved just fine now.

  • Modification Comparison - No Changes Possible

    Hi,
    I have a program which has been modified (SAPLRSM1) with the implementation of a SAP note 987566.  This has made a change which has appended two parameters to an include, which is giving a syntax error.
    SAP Note 990672 looks to fix the problem by removing one of the parameters, but I cannot implement this note as it seems to be obsolete, and has the status Implementation Status: Cannot be implemented .
    I know exactly where the error is in the code and in the short term want to comment out the parameter which is giving me an issue, but when I go to change the include, I get the message:
    Carry out modification comparison for CPUB CL_RSCRT_RDA_TOOLS first. No changes possible
    I have ran the modification comparison, but I do not get any further options.
    Could somebody tell me where I am going worng and whether it is possible for me to make this change in this way.
    We have SAP helping with some work which we are doing on our new 2004's box, but I need to get this part working urgently.
    Thanks
    DJL

    Dear Michael,
    Could you please tell us that in recent days have you upgraded patch of any SAP component in your system? Please check in your system is there any SAP Note in inconsistent status in your system. You can see the status in tcode SNOTE.
    As per suggessted by Ruchit , please take the help of ABAPers & resolve the issue.
    Let us know the status.
    Thank You.
    Kind Regards,
    Rafikul Hussain

  • Dns resolve some website slowly

    Dns is resolving a lot of website quickly, but there are some websites like cnn.com , bbc.com take around 15 second to resolve the host name , I used nslookup then ping cnn.com and bbc.com and then take time also . I have 2 dns , and I have 3 dns for
    isp and when I changed my dns and put any of isp dns I can open any website so fast, before all websites were opening fine but now I have that issue, and I check all configuration and connectivity all work great, OS Win server 2008 r2 and clients
    win 7 and xp.

    check the workload of your DNS
    how many users in your environment?
    http://technet.microsoft.com/en-us/library/cc778608(v=ws.10).aspx
    Monitoring DNS server performance
    Every second counts..make use of it. Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    IT Stuff Quick Bytes

  • My modem works just fine, but my airport extreme refuses to connect to the internet.  I even reset it more than once, changed the DNS servers and still nothing.  Help

    Ok so recently we were having problems with our phone.  We had to disconnect our modem in order to fix the phone lines and when that happened, our airpot extreme disconnected itself from the internet.  No matter what I did i could not get it to connect back.  I would power down the modem, I would reset the AE and nothing would happen.
    I tried changing the DNS server and nothing happened.  I always get the same messages in the airport utility app: No internet connection and no DNS server
    Nothing I seem to do works.  I do know for a fact though, that the problem is not the modem.  I have connected it through ethernet to other devices and the internet has worked just fine. 
    Please please please if anybody sees this help me out!!

    Since you feel good about having internet access up to your Airport, I would suggest as a next step checking your Airport's status light to see if it is giving any clues as to what may be going on. Below is some info on what the light can indicate
    AirPort Express Status light sequences and what they indicate.
    No light (Off) - AirPort Express is unplugged
    Solid green - AirPort Express is on and working properly.
    Flashing amber - AirPort Express is not set up or cannot establish a connection to the network or
    the Internet. Use AirPort Utility to find out the cause. See “If Your AirPort Express
    Status Light Flashes Amber” on page 20.
    Solid amber - AirPort Express is starting up.
    Flashing amber and green - There may be a problem starting up. AirPort Express will restart

Maybe you are looking for

  • How to autopopulate a text field with unique data from multiple data sets

    Hi, I'm a laboratory manager in charge of a hospital project which will be using pdf forms to send and receive data from our end users across the city. I need help with the last part of our pdf form, specifically with a js that will do a bit of text-

  • 2 questions for 1 part of my app

    Hello there, I have a report and form in my APEX application, and right now the form adds entries into the report, which aggregates the data into 1 row if the name is the same. (terrible explanation but if you take a look at my app then maybe you wil

  • Error for Communication Channel Monitoring

    Hi Getting the following error when trying to read the file using Content Conversion. Conversion of file content to XML failed at position 0: java.lang.Exception: ERROR converting document line no. 2 according to structure 'Tivoli_Row':java.lang.Exce

  • Can't get granular file .bak or .cmp to restore.

    I made a granular backup of my site collection into .bak. and now im trying to import said file by using I have the site I'm importing to already created at http:/testserver/sites/test Import-SPWeb -identity http:testserver/sites/test -path \\shareds

  • Illustrator CC - Tools not allowing access to drop-down options

    Illustrator CC - Tools not allowing access to drop-down options For example, I want to change the shape from rectangle to an oval, the press and hold on the rectangle shape (by default) will not give access to other shape options.  Or, for another ex