SSH 2 Error

Guys,
Have you ever seen this log? What does that mean?
This log was exist when I tried to connect with ssh v2 to the Router with SecureCRT. And I couldn't connect to the Router.
Jul 19 09:45:49.455 IND: SSH2 1:  Invalid modulus length
Thanks.

I am in the process of implementing SSH on all our network hardware. I am receiving this same error on two routers out of the several dozen I have done so far. I can connect using SecureCRT version 5 to all the routers so far except of these two. Some of the routers are 2811s and some are newer 2911s. The two that I am receiving the error message on are running c2900-universalk9-mz.SPA.150-1.M4.bin and c2900-universalk9-mz.SPA.150-1.M3.bin. The other 2911s I have are running c2900-universalk9-mz.SPA.151-4.M1.bin I have compared the sh SSH information from both a working and non working router and they look basically the same. I am using the same script to enable SSH on all the hardware so am now wondering if there is a bug in the IOS? I have zeroized the RSA  and recreated with no change. I also have noticed that the key is not listed in the config as in the working routers.
Script:
ip domain name {mydomain}
ip ssh time-out 60
ip ssh authentication-retries 3
ip ssh version 2
crypto key generate rsa general-keys modulus 1024
line vty 0 4
no privilege level 15
login local
transport input ssh
line vty 5 15
no privilege level 15
login local
transport input ssh
working:
Phoenix_r#sh ip ssh
SSH Enabled - version 2.0
Authentication timeout: 60 secs; Authentication retries: 3
Minimum expected Diffie Hellman key size : 1024 bits
IOS Keys in SECSH format(ssh-rsa, base64 encoded):
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQDd0h7KPpDkU+aVbyBa44UFqNo7a64JXMD5
rTYj+MNIfmG+6z1av5G0Pgd9YvbsEjw1XMdMZzxOuq6537ntNSoUurn8ZbXCCGd5
EQwb6cjdpk4bnM96iobZEqGktY4yza031JtS8Wz+ts9zb5WSjnALiSq6xR2pXgCi
KDVgi3lBCw==
Phoenix_r#
non-working:
Carrollton_r#sh ip ssh
SSH Enabled - version 2.0
Authentication timeout: 60 secs; Authentication retries: 3
Minimum expected Diffie Hellman key size : 1024 bits
IOS Keys in SECSH format(ssh-rsa, base64 encoded):
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQC0hG9r5Srg8mvIQlVZU2vJYakJug2OWeRp
XBq33iHki9CE3XT0mrmkH7cZegwuQ+tzyeMqSrZhNbzPFXnVadK1C9F5NI7hPnlx
8RRF7x2rgrvmTfb17MWdnNW/MLkS/d/Z8zyLyFOP4p0wGqgieZBNrj3mzr2rNkjA
sGiSlJ8Aow==
Carrollton_r#

Similar Messages

  • SSH Error in the /var/adm/messages

    Dears
    I Have an error that appers many times in the system messages file,
    **sshd[5437]: [ID 800047 auth.crit] fatal: Read from socket failed: Connection reset by peer**
    i disabled the telnet and use the SSH to connect to the system, i dont have any problems in SSH my System but i always notice this error in the /var/adm/messages, does anyone knows what is this error and why it is generated?
    thanks

    Dear All i am also having the same problems
    No1: MY SEVER T1000 having this problem,
    Server was installed with jumpstart
    Connection to 172.16.14.52 closed by foreign host.
    # ssh 172.16.14.52
    @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
    IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
    Someone could be eavesdropping on you right now (man-in-the-middle attack)!
    It is also possible that the RSA host key has just been changed.
    The fingerprint for the RSA key sent by the remote host is
    69:15:c9:67:86:a4:43:95:9e:7d:d6:70:78:ea:46:cb.
    Please contact your system administrator.
    Add correct host key in /.ssh/known_hosts to get rid of this message.
    Offending key in /.ssh/known_hosts:3
    RSA host key for 172.16.14.52 has changed and you have requested strict checking.
    Host key verification failed
    No2: sshd[4070]: [ID 800047 auth.crit] fatal: Read from socket failed:Connection reset by peer
    any body can help me..

  • Getting ssh error while starting 10g cluster installation

    Hi frnds
    I am getting the following error while running 10g clusterware installation.Actually i done the ssh setup mentioned in the oracle doc.Generated both keys (rsa,dsa) on both nodes and copied these 2 files from both nodes to authorized_key file and copy this file to both nodes and ran $shell and ssh-add.Whenever i logs and run this SSH User Equivalency on node1(from where i run oui) and its persisting with other sessions but if logoff and logon i have to run the $shell and ssh-add to enable it.My dought is whether this ssh have to enable always or only while using OUI to install and applying patches cos this Equivalency dont need to run on second node correct ?
    Caught Cluster Exception PRKC-1044 : Failed to check remote command execution setup for node racdb1.bsa.net.in using shells /usr/bin/ssh and /usr/bin/rsh
    racdb1.bsa.net.in: Connection refused
    rgds
    rajesh

    Hi
    thnks for that but when i run that exec $SHELL and ssh-add again in one session i can do ssh it other sessions without any problem but if i logoff and login it will reset to back.Whether this ssh have to enabled on first node(where i run OUI) always irrespective of logons and logout or whether i have to start any services ?
    rgds
    rajesh

  • SSH Error, While discovering AIX system~~~SCOM 2012 R2

    Hi Guys,
    While discovery linux system (AIX OS), I am getting below error.
    In my linux machine telnet port 23 in open so i am using 23 port in replace 22 port.

    SSH on Linux machine run on port 22 so that you have previous error. Secondly, port 23 is used for Telnet not for SSH. you can't change ports to reserved range like 23, 25, 110 because those ports reserved for specific services
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • Avanti ssh error need a server browser to move files

    I need a server browser so I can edit / add some files on my firewall I tryed to use avanti ssh server browser but I get an error saying
    "failed to connect to avanti server daemon not running
    " so how can I get this running or how do I config it to get it to work? Or is there something better? I also tried " ssh -p xxx me_@myfirewall" but I get
    bash: ssh: command not found

    You need to install openssh first: http://wiki.archlinux.org/index.php/SSH
    I don't know about avanti, but most arch deamons can be started by running
    /etc/rc.d/<deamon> start

  • Terminal SSH Error

    I recently posted, this question in the SL category, and moved when I was told I posted it in the wrong place. So, when I execute:
    ssh Denny [email protected]
    I get the following error in return:
    ssh: Could not resolve hostname Denny nor servname provided or not known
    I then executed:
    echo $USER
    And got the following readout:
    Denny L
    What is the problem?

    For future reference, is posting the account names or computer
    name a good idea, or a not-so-great idea?
    Yes and No.
    If these systems are basically living behind a router and not
    accessable to the outside world, then only people with access
    to your system.
    In my case I use my real name as my public name, so it is an easy
    guess for someone to figure out I use 'harris' as my Mac OS X short
    name.
    I do not generally publish my system name, and I never publish an
    internet accessable DNS name nor an IP address that is accessable
    via the internet. I will publish 10..*. and 192.168.. addresses
    as these are private non-routing IP addresses used by home routers
    for private networks not accessable from the internet.
    But if you feel uncomfortable using real names, IP address,
    or system names, then use pseudo names and addresses,
    such as '[email protected]'
    or '[email protected]'
    or '[email protected]'
    or '[email protected]',
    etc...
    If you follow the basic pattern, most people will figure out
    what you mean, without giving out any information.

  • Ssh Error: Can't open display:

    Hi all,
    So I am fairly new to the whole Bash shell business but please bear with me. I am a student working on a research project and need to ssh through one computer into another in order to do my work (one has access to the other). On the second computer (computer B), I am going to need to use X11 to open up graphical programs that exist outside of terminal. I have successfully sshed from the 1st computer (computer A, an iMac which runs the 10.5.8 software) to computer B using ssh -Y [email protected] and can successfully open programs like firefox in an X11 window without having to set the DISPLAY variable.
    The problem arises when I begin by using my laptop (a MacBook that runs 10.5.8 as well) to first ssh into computer A, and then into B. I can successfully log into my account on both computers by using ssh -Y [email protected] and then ssh -Y [email protected]. However, I cannot open programs such as xclock or firefox on either computer A or B from terminal on my macbook. When i type echo $DISPLAY on my macbook, it returns an empty line, unlike when I do so from the screen on computer A sshed into computer B (it generally has DISPLAY=localhost:##.0). I have tried using the -X flag and have also tried to manually set my DISPLAY variable by using a number of different combinations of localhost, ip adresses, etc and still cannot figure out how to get this thing to work.
    Other useful facts:
    -I have reviewed the ssh_config and sshd_config files on my macbook and on computer A, and they are nearly identical, and are identical with respect to X11 forwarding
    -I have also tried this on another identical macbook, and on a brand new 15 inch macbook pro and they both sshed in with empty DISPLAY variables
    -my system preferences under the sharing tab of my macbook are the same as on computer A
    -I can get firefox on computer B to display in X11 on computer A by using my macbook when I know the value of the DISPLAY variable for computer A
    -I do not have any code that alters the behavior of DISPLAY in my .profile, .bashrc, etc.
    -echo $DISPLAY when not sshed into any computer reads /tmp/launch-_ _ _ _ _ _/:0 on both my macbook and computer A where the spaces underscores are filled with random numbers or letters (as with most macs, I think)
    If there is any other information that is useful here, please feel free to ask. I just want to figure this out so I can get to work.
    Cheers!

    This would be better discussed in the Mac OS X Technologies > Unix Forum
    <http://discussions.apple.com/forum.jspa?forumID=735>
    where Unix aware users hang out.
    Try
    ssh -t -Y [email protected] ssh -t -Y [email protected]
    That is just 1 command line. It is NOT 2 lines.
    You are cascading the ssh logins via the same command line.
    I've done this and it worked for me. Both systems fully support X11. If I used a middle system that does not support X11, the chain was broken.
    Another approach would be to tunnel through a tunnel using system A as the bridging system. So from your Mac:
    ssh -N -L 50022:web.address.B.com:22 [email protected] &
    You now have a tunnel to system A which will redirect anything sent to port 50022 to system B's sshd daemon.
    Now still on your Mac you take advantage of that first tunnel
    ssh -p 50022 -Y usernameB@localhost
    Now you have a single ssh connection from your Mac to system B, with X11 forwarding enabled. You should be able to start an X11 based App on system B, and it will send its display output to your Mac.
    I played with xclock to make sure it worked for me.
    The advantage of this 2nd approach is that the middle system A does not need to have X11 support as it is not being asked to do anything except forward the ssh port to system B.

  • Ssh error

    I setup ssh on my arch box, but when I try to connect to it I get:
    SSH_exchange_identification: Connection closed by remote host
    I followed the guide on the wiki so I'm not sure what is wrong.
    Any ideas?
    nomb

    yeah, I had the same problem too the first time i setup my ssh.
    Add
    sshd:ALL
    to /etc/hosts.allow file
    if you are behind router/firewall make sure to port forward port  nr 22 to your computer.

  • Error making an ssh tunnel

    I'm getting an error trying to create an ssh tunnel.
    *ssh –L 10548:localhost:548 [email protected]*
    returns
    *ssh: Error resolving hostname \342\200\223L: nodename nor servname provided, or not known*
    normal ssh works ok so the problem is with localhost. This only happens on one of my computers. the other one connects fine using the same internet connection.
    P.S. I just checked and this only happens on one user account. the rest are fine.
    Message was edited by: V.K.
    this thread is the continuation of [this one|http://discussions.apple.com/thread.jspa?messageID=7218912#7218912].
    Message was edited by: V.K.

    Very strange. I wonder what \342\200\223L means. You can create a tunnel to the same [email protected] from another account on the same client Mac?
    The localhost parameter is actually sent to the server, i.e. it means that sshd should connect port 548 on localhost. What if you put "10548:localhost:548" in quotes? Or try "*ssh –L 10548:my.computer.at.work:548 [email protected]*". You could also try moving or renaming your local ~/.ssh folder to make sure there are no local user settings that are confusing things.

  • Root login is blocked from telnet ssh pam_unix_session: Can't write lastlog: uid 0: I/O error

    Root login is blocked from telnet ,ssh  error : pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[1969]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[1970]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[1983]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[1984]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[2023]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[2021]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    genunix: vn_rdwr failed with error 0x6
    genunix: kobj_load_module: smp read header failed
    genunix: vn_rdwr failed with error 0x6
    genunix: kobj_load_module: ses read header failed
    sshd[2037]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    sshd[2035]: pam_unix_session: Can't write lastlog: uid 0: I/O error
    please suggest for the issue , occurs frequently in solaris 10

    please verify your underlying hardware

  • Unable to connect to ACE30 from 3845/2811 -ssh - Invalid modulus length

       Hi,
    I`ve seen quite a lot of posts regarding SSH issues and the above SSH error. However the fix mainly involves upgrading clients but in this instance the client is are Cisco routers 3845 / 2811 - which we use for out and inband management.
    Connectivity / routing etc is proven. Using SSH v2 the actual 6500 chassis where the ACE is physically located works fine. Configuring SSH v1 on the ACE module allows connections via the 3845/2811`s but we cannot use this.
    Both have the following IOS Version 12.4(24)T4. I have tried various key sizes on the ACE module.
    The SSH debug is :
    Aug  8 09:44:00.755: SSH2 CLIENT 2: SSH2_MSG_KEXINIT sent
    Aug  8 09:44:00.767: SSH2 CLIENT 2: ssh_receive: 536 bytes received
    Aug  8 09:44:00.767: SSH2 CLIENT 2: input: total packet length of 776 bytes
    Aug  8 09:44:00.767: SSH2 CLIENT 2: partial packet length(block size)8 bytes,nee                                                                                                                                                             ded 768 bytes,
                   maclen 0
    Aug  8 09:44:00.767: SSH2 CLIENT 2: ssh_receive: 240 bytes received
    Aug  8 09:44:00.767: SSH2 CLIENT 2: partial packet length(block size)8 bytes,nee                                                                                                                                                             ded 768 bytes,
                   maclen 0
    Aug  8 09:44:00.767: SSH2 CLIENT 2: input: padlength 10 bytes
    Aug  8 09:44:00.767: SSH2 CLIENT 2: SSH2_MSG_KEXINIT received
    Aug  8 09:44:00.767: SSH2:kex: server->client enc:aes128-cbc mac:hmac-sha1
    Aug  8 09:44:00.767: SSH2:kex: client->server enc:aes128-cbc mac:hmac-sha1
    Aug  8 09:44:00.767: SSH2 CLIENT 2: send:packet of  length 24 (length also inclu                                                                                                                                                             des padlen of 6)
    Aug  8 09:44:00.767: SSH2 CLIENT 2: SSH2_MSG_KEX_DH_GEX_REQUEST sent
    Aug  8 09:44:00.767: SSH2 CLIENT 2: Range sent- 1024  < 2048  < 4096
    Aug  8 09:44:00.859: SSH2 CLIENT 2: ssh_receive: 424 bytes received
    Aug  8 09:44:00.863: SSH2 CLIENT 2: input: total packet length of 424 bytes
    Aug  8 09:44:00.863: SSH2 CLIENT 2: partial packet length(block size)8 bytes,nee                                                                                                                                                             ded 416 bytes,
                   maclen 0
    Aug  8 09:44:00.863: SSH2 CLIENT 2: input: padlength 10 bytes
    Aug  8 09:44:00.863: SSH2 CLIENT 2: SSH2_MSG_KEX_DH_GEX_GROUP received
    Aug  8 09:44:00.863: SSH2 CLIENT 2:
    Invalid modulus length
    Is there a fix for this issue ?
    Many thanks for any tips/advise.

    I`ve now tried a new version of the code incase it was a bug. ( 12.4 (24) T6 ) and various key sizes ( 768, 1024,2048, 4096) but no avail.
    Oct 12 13:16:26.435: SSH CLIENT0: protocol version id is - SSH-2.0-OpenSSH_5.2
    Oct 12 13:16:26.435: SSH CLIENT0: sent protocol version id SSH-2.0-Cisco-1.25
    Oct 12 13:16:26.435: SSH CLIENT0: protocol version exchange successful
    Oct 12 13:16:26.435: SSH2 CLIENT 0: SSH2_MSG_KEXINIT sent
    Oct 12 13:16:26.447: SSH2 CLIENT 0: SSH2_MSG_KEXINIT received
    Oct 12 13:16:26.447: SSH2:kex: server->client enc:aes128-cbc mac:hmac-sha1
    Oct 12 13:16:26.447: SSH2:kex: client->server enc:aes128-cbc mac:hmac-sha1
    Oct 12 13:16:26.447: SSH2 CLIENT 0: SSH2_MSG_KEX_DH_GEX_REQUEST sent
    Oct 12 13:16:26.447: SSH2 CLIENT 0: Range sent- 1024  < 2048  < 4096
    Oct 12 13:16:26.535: SSH2 CLIENT 0: SSH2_MSG_KEX_DH_GEX_GROUP received
    Oct 12 13:16:26.535: SSH2 CLIENT 0:
    Invalid modulus length
    Oct 12 13:16:26.535: SSH CLIENT0: key exchange failure (code = 0)
    Oct 12 13:16:26.535: SSH CLIENT0: Session disconnected - error 0x00

  • SSH exception

    We are connecting to servers VIA sftp and say we are moving three files well sometimes in the middle we get an SSH reset connection exception and then the process fails. This happens in our BPEL and our ESB so. From what I have noticed the one bpel project will cause this problem if we try three files we try two there is no problem we try no problem either. Only when we have three files, And i know people would think maybe file size and TTL on the SFTP connection but if you combine all three files the size ='s 1.5 MB TTL is 6 minutes. We calculated the current time and its about 1:40 to complete. Its like the program just throws this exception whenever it pleases, and at first I thought it was just BPEL but i was looking throguh the logs and ESB has this occuring also
    bold the above was osted before we found out that SOA is not causing these SSH errors it is a router or server or something to that nature
    Well besides getting rid of the error how can we handle it? Some kind of exception handling? Please exaplain how or where I can go as for a website explaining it. Like if we get an SSH error half way through we want to be able to save whatever started maybe rollback sort of to as if nothing happened. What you be the standard for putting in an exeption handler that will be initiated off SSH error. To make things simple we will put our code in a scope and add a catch all in there. Now I have done this but inside of my scaop I tried to include an compensate but it said it could find no scaopes :( tried to hard code the scope name and it yelled and deploy time. Anyone got some ideas?

    I have seen this when there is a loadbalancer infront of the FTP server.
    Even if you don't try the following
    on the FTP adapter set the following properties (Right-Click the adapter -> edit -> property tab) If successful you should see the entry in the bpel.xml file.
    useJCAConnectionPool=true
    cacheConnections=false
    In the oc4j-ra.xml connection factory for FTP set the property
    keepConnections=false
    cheers
    James

  • Unusual 8003 error - iTunes - Purchases or Apps

    Experiencing this error on a Win7 based machine, MacBook Pro and iPad 2 under the same profile.  I am able to access and browse the store Ok, I am able to make purchases, songs, books, apps etc however, they simply will not download and the 8003 error is experienced.  I followed Apple Q's steps -  HT2292, TS1368 but no joy.  All devices access the net via my home network device, a Linksys X3000 modem/router with latest firmware update.
    One option I tried that did work was to tether my cell/mobile phone to my iPad and was able to download all updates to Apps and book purchases to my iPad.  The cell phone accesses the interent via my providers 3G network and not via my home network and ISP.  However, when I sync the iPad to either the Win 7 or Mac Book the new downloads and updates will not sync with iTunes on either device.  My purchases still show up as available downloadable content in iTunes for either device. 
    I checked to see whether the problem is experenced for other forms of content on iTunes.  I purchased a song via iTunes and experienced the same 8003 error, so the problem is not isolated to books alone.  All current relevant updates for OS's to Win7, MacBook and iPad have been applied.  This is not a firewall problem as I can access the store fine.  The last time I accessed the store prior to this was about 1 month ago and everything worked fine. 

    Very interesting! I'm having the exact same problem but am using a Linksys X2000.   Everything was working great until I upgraded the firmware yesterday.  Since then, I'm unable to download anything from iTunes (-8003 error) on the AppleTV or my PC, but I can still browse the Apple store and watch previews.
    I've restored the router to factory settings a few times just to be sure something wasn't disabled. 
    Interestingly, I'm also unable to connect to GW2 at all, and another website I regulaly log into won't redirect.  It seems something is blocking certain ports or traffic.  I thought maybe some sort of SSH error, but some sites I can log into just fine (like Gmail for instance).
    Going to try it with another modem / router to see if I have any luck.

  • Mars Device Discovery with SSH

    I am trying to add a device (switch) to the Mars appliance. When selecting access type as SSH, I get an error, 'not able to log in... username/password failed'. Using the same username and password, I change the access type to telnet. Mars discovers the switch with no trouble. The SSH error includes the string it uses to connect 'ssh -c 3des -l username 1.1.1.1' I can successfully access the switch with the same string from the Mars command line. I have retyped the username and password a dozen plus times with no success. Any ideas?

    It look like bug to me, check this bug-id CSCsi03658.

  • Leopard, DNS trouble with CNAMES

    Hello,
    Hopefully someone in the forums will be able to help me out with this. Apple's phone support for this problem was extremely frustrating and left me extremely disappointed with the company and the purchase of my first Mac. The "2nd teir" support technician couldn't even adequately describe to me what DNS does and refused to transfer me to a more qualified technician.
    I've found that Leopard does not seem to handle DNS CNAME -> IP address lookups. An example is listed below. This is not limited to SSH. I have problems with HTTP connections as well. It's just easier to post the text. Has anyone else encountered this and come up with a solution?
    cncuxmbp01:~ kcurrie$ nslookup splunk.tare.local
    Server: 161.179.68.76
    Address: 161.179.68.76#53
    splunk.tare.local canonical name = cncux1z06.us.aegon.com.
    Name: cncux1z06.us.aegon.com
    Address: 161.179.77.141
    cncuxmbp01:~ kcurrie$ ssh splunk.tare.local
    ssh: Error resolving hostname splunk.tare.local: nodename nor servname provided, or not known

    The problem is that dot-local names are looked up using Multicast DNS on Mac OS X. Trying adding "local" to your list of search domains in the Network pref pane. That will work around the problem.

  • LAMP will not install

    I'm following the LAMP guide on the wiki here: http://wiki.archlinux.org/index.php/LAMP and when I try downloading the packages, I get the following:
    [root@Firefly ssh]# pacman -S apache php php-apache mysql
    resolving dependencies...
    looking for inter-conflicts...
    Targets (12): apr-1.4.2-1 libsasl-2.1.23-4 libldap-2.4.21-2
    unixodbc-2.3.0-1 apr-util-1.3.9-4 apache-2.2.15-2
    libxml2-2.7.7-1 php-5.3.2-6 php-apache-5.3.2-6
    libmysqlclient-5.1.47-1 mysql-clients-5.1.47-1 mysql-5.1.47-1
    Total Download Size: 16.18 MB
    Total Installed Size: 159.37 MB
    Proceed with installation? [Y/n] Y
    :: Retrieving packages from extra...
    libmysqlclient-5.1.... 8.2M 2.9M/s 00:00:03 [#####################] 100%
    error: failed retrieving file 'mysql-5.1.47-1-x86_64.pkg.tar.xz' from mirrors.kernel.org
    warning: failed to retrieve some files from extra
    error: failed to commit transaction (failed to retrieve some files)
    Errors occurred, no packages were upgraded.
    [root@Firefly ssh]# error: failed retrieving file 'mysql-5.1.47-1-x86_64.pkg.tar.xz' from mirrors.kernel.org
    -bash: error:: command not found
    Help me... please.

    Seems like the mirror is not fully synced yet.
    Wait som time: run "pacman -Syu" and then try again

Maybe you are looking for