Web lists-archives.com

Re: ssh




Op maandag 12 november 2018 14:49:23 CET schreef Alan Taylor:
> Greetings,
> 
> I have an ssh problem - one user can use it successfully, another cannot. I
> have checked and rechecked permissions until I am blue in the face … At the
> moment just trying to ssh into the same machine I am on for the problem
> user (the other user can ssh successfully, both to the console machine and
> outwards to others). Agent problem ? The successful user was setup in the
> installation, the problem user was added at the command line after initial
> setup.
> 
> Log output follows, appears to fail after the preauth stage …
> 
> Any suggestions gratefully accepted
> 
> root@sirius/etc/ssh # journalctl | grep sshd | grep "Nov 12 13:45"
> Nov 12 13:45:17 sirius sshd[3155]: debug3: fd 4 is not O_NONBLOCK
> Nov 12 13:45:17 sirius sshd[3155]: debug1: Forked child 3241.
> Nov 12 13:45:17 sirius sshd[3155]: debug3: send_rexec_state: entering fd = 7
> config len 650 Nov 12 13:45:17 sirius sshd[3155]: debug3: ssh_msg_send:
> type 0
> Nov 12 13:45:17 sirius sshd[3241]: debug3: oom_adjust_restore
> Nov 12 13:45:17 sirius sshd[3155]: debug3: send_rexec_state: done
> Nov 12 13:45:17 sirius sshd[3241]: debug1: Set /proc/self/oom_score_adj to 0
> Nov 12 13:45:17 sirius sshd[3241]: debug1: rexec start in 4 out 4 newsock 4
> pipe 6 sock 7 Nov 12 13:45:17 sirius sshd[3241]: debug1: inetd sockets
> after dupping: 3, 3 Nov 12 13:45:17 sirius sshd[3241]: Connection from
> 192.168.8.3 port 39668 on 192.168.8.3 port 50400 Nov 12 13:45:17 sirius
> sshd[3241]: debug1: Client protocol version 2.0; client software version
> OpenSSH_7.4p1 Debian-10+deb9u4 Nov 12 13:45:17 sirius sshd[3241]: debug1:
> match: OpenSSH_7.4p1 Debian-10+deb9u4 pat OpenSSH* compat 0x04000000 Nov 12
> 13:45:17 sirius sshd[3241]: debug1: Local version string
> SSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u4 Nov 12 13:45:17 sirius sshd[3241]:
> debug1: Enabling compatibility mode for protocol 2.0 Nov 12 13:45:17 sirius
> sshd[3241]: debug2: fd 3 setting O_NONBLOCK Nov 12 13:45:17 sirius
> sshd[3241]: debug3: ssh_sandbox_init: preparing seccomp filter sandbox Nov
> 12 13:45:17 sirius sshd[3241]: debug2: Network child is on pid 3242 Nov 12
> 13:45:17 sirius sshd[3241]: debug3: preauth child monitor started Nov 12
> 13:45:17 sirius sshd[3241]: debug3: privsep user:group 117:65534 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: permanently_set_uid: 117/65534
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3: ssh_sandbox_child:
> setting PR_SET_NO_NEW_PRIVS [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: ssh_sandbox_child: attaching seccomp filter program [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug1: list_hostkey_types:
> ssh-ed25519,ssh-rsa,rsa-sha2-512,rsa-sha2-256 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: send packet: type 20 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug1: SSH2_MSG_KEXINIT sent [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: receive packet: type 20 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug1: SSH2_MSG_KEXINIT received [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: local server KEXINIT proposal
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2: KEX algorithms:
> curve25519-sha256,curve25519-sha256@xxxxxxxxxx,ecdh-sha2-nistp256,ecdh-sha2
> -nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hel
> lman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha
> 256,diffie-hellman-group14-sha1 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug2: host key algorithms: ssh-ed25519,ssh-rsa,rsa-sha2-512,rsa-sha2-256
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2: ciphers ctos:
> chacha20-poly1305@xxxxxxxxxxx,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@o
> penssh.com,aes256-gcm@xxxxxxxxxxx[preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug2: ciphers stoc:
> chacha20-poly1305@xxxxxxxxxxx,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@o
> penssh.com,aes256-gcm@xxxxxxxxxxx[preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug2: MACs ctos:
> umac-64-etm@xxxxxxxxxxx,umac-128-etm@xxxxxxxxxxx,hmac-sha2-256-etm@openssh.
> com,hmac-sha2-512-etm@xxxxxxxxxxx,hmac-sha1-etm@xxxxxxxxxxx,umac-64@openssh.
> com,umac-128@xxxxxxxxxxx,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: MACs stoc:
> umac-64-etm@xxxxxxxxxxx,umac-128-etm@xxxxxxxxxxx,hmac-sha2-256-etm@openssh.
> com,hmac-sha2-512-etm@xxxxxxxxxxx,hmac-sha1-etm@xxxxxxxxxxx,umac-64@openssh.
> com,umac-128@xxxxxxxxxxx,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: compression ctos: none [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: compression stoc: none [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: languages ctos: [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: languages stoc: [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: first_kex_follows 0 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: reserved 0 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug2: peer client KEXINIT proposal
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2: KEX algorithms:
> curve25519-sha256,curve25519-sha256@xxxxxxxxxx,ecdh-sha2-nistp256,ecdh-sha2
> -nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hel
> lman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-excha
> nge-sha1,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-
> c [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2: host key algorithms:
> ssh-ed25519-cert-v01@xxxxxxxxxxx,ssh-ed25519,ecdsa-sha2-nistp256-cert-v01@o
> penssh.com,ecdsa-sha2-nistp384-cert-v01@xxxxxxxxxxx,ecdsa-sha2-nistp521-cert
> -v01@xxxxxxxxxxx,ssh-rsa-cert-v01@xxxxxxxxxxx,ecdsa-sha2-nistp256,ecdsa-sha2
> -nistp384,ecdsa-sha2-nistp521,rsa-sha2-512,rsa-sha2-256,ssh-rsa [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug2: ciphers ctos:
> chacha20-poly1305@xxxxxxxxxxx,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@o
> penssh.com,aes256-gcm@xxxxxxxxxxx,aes128-cbc,aes192-cbc,aes256-cbc [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug2: ciphers stoc:
> chacha20-poly1305@xxxxxxxxxxx,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@o
> penssh.com,aes256-gcm@xxxxxxxxxxx,aes128-cbc,aes192-cbc,aes256-cbc [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug2: MACs ctos:
> umac-64-etm@xxxxxxxxxxx,umac-128-etm@xxxxxxxxxxx,hmac-sha2-256-etm@openssh.
> com,hmac-sha2-512-etm@xxxxxxxxxxx,hmac-sha1-etm@xxxxxxxxxxx,umac-64@openssh.
> com,umac-128@xxxxxxxxxxx,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: MACs stoc:
> umac-64-etm@xxxxxxxxxxx,umac-128-etm@xxxxxxxxxxx,hmac-sha2-256-etm@openssh.
> com,hmac-sha2-512-etm@xxxxxxxxxxx,hmac-sha1-etm@xxxxxxxxxxx,umac-64@openssh.
> com,umac-128@xxxxxxxxxxx,hmac-sha2-256,hmac-sha2-512,hmac-sha1 [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: compression ctos:
> none,zlib@xxxxxxxxxxx,zlib [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug2: compression stoc: none,zlib@xxxxxxxxxxx,zlib [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: languages ctos: [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: languages stoc: [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: first_kex_follows 0 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug2: reserved 0 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: kex: algorithm: curve25519-sha256
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1: kex: host key
> algorithm: ssh-ed25519 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1:
> kex: client->server cipher: chacha20-poly1305@xxxxxxxxxxx MAC: compression:
> none [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1: kex:
> server->client cipher: chacha20-poly1305@xxxxxxxxxxx MAC: compression: none
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1: expecting
> SSH2_MSG_KEX_ECDH_INIT [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> receive packet: type 30 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_key_sign entering [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_request_send entering: type 6 [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug3: mm_key_sign: waiting for MONITOR_ANS_SIGN [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive_expect entering:
> type 7 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_receive entering [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_request_receive entering Nov 12 13:45:17 sirius sshd[3241]:
> debug3: monitor_read: checking request 6 Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_answer_sign
> Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_sign: hostkey proof
> signature 0x558f44056a40(83) Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_send entering: type 7 Nov 12 13:45:17 sirius sshd[3241]: debug2:
> monitor_read: 6 used once, disabling now Nov 12 13:45:17 sirius sshd[3241]:
> debug3: send packet: type 31 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: send packet: type 21 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug2: set_newkeys: mode 1 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug1: rekey after 134217728 blocks [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug1: SSH2_MSG_NEWKEYS sent [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug1: expecting SSH2_MSG_NEWKEYS [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: send packet: type 7 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: receive packet: type 21 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug1: SSH2_MSG_NEWKEYS received [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug2: set_newkeys: mode 0 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug1: rekey after 134217728 blocks [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: KEX done [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug3: receive packet: type 5 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug3: send packet: type 6 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug3: receive packet: type 50 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: userauth-request for user
> backuppc service ssh-connection method none [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug1: attempt 0 failures 0 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: mm_getpwnamallow entering [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug3: mm_request_send entering: type 8
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_getpwnamallow:
> waiting for MONITOR_ANS_PWNAM [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_request_receive_expect entering: type 9 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug3: mm_request_receive entering [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive entering Nov
> 12 13:45:17 sirius sshd[3241]: debug3: monitor_read: checking request 8 Nov
> 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_pwnamallow
> Nov 12 13:45:17 sirius sshd[3241]: debug2: parse_server_config: config
> reprocess config len 650 Nov 12 13:45:17 sirius sshd[3241]: debug3:
> auth_shadow_acctexpired: today 17847 sp_expire -1 days left -17848 Nov 12
> 13:45:17 sirius sshd[3241]: debug3: account expiration disabled Nov 12
> 13:45:17 sirius sshd[3241]: debug3: auth2_setup_methods_lists: checking
> methods Nov 12 13:45:17 sirius sshd[3241]: debug1: authentication methods
> list 0: publickey Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_answer_pwnamallow: sending MONITOR_ANS_PWNAM: 1 Nov 12 13:45:17 sirius
> sshd[3241]: debug3: mm_request_send entering: type 9 Nov 12 13:45:17 sirius
> sshd[3241]: debug2: monitor_read: 8 used once, disabling now Nov 12
> 13:45:17 sirius sshd[3241]: debug2: input_userauth_request: setting up
> authctxt for backuppc [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_inform_authserv entering [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_request_send entering: type 4 [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug3: mm_auth2_read_banner entering [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: mm_request_send entering: type 10 [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive_expect entering:
> type 11 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_receive entering [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_request_receive entering Nov 12 13:45:17 sirius sshd[3241]:
> debug3: monitor_read: checking request 4 Nov 12 13:45:17 sirius sshd[3241]:
> debug3: mm_answer_authserv: service=ssh-connection, style=, role= Nov 12
> 13:45:17 sirius sshd[3241]: debug2: monitor_read: 4 used once, disabling
> now Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive entering
> Nov 12 13:45:17 sirius sshd[3241]: debug3: monitor_read: checking request
> 10 Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_send entering:
> type 11 Nov 12 13:45:17 sirius sshd[3241]: debug2: monitor_read: 10 used
> once, disabling now Nov 12 13:45:17 sirius sshd[3241]: debug3: send packet:
> type 53 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1:
> userauth_send_banner: sent [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: auth2_setup_methods_lists: checking methods [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug1: authentication methods list 0:
> publickey [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2: Unrecognized
> authentication method name: none [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug3: userauth_finish: failure partial=0 next
> methods="publickey" [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> send packet: type 51 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> receive packet: type 50 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug1: userauth-request for user backuppc service ssh-connection method
> publickey [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug1: attempt 1
> failures 0 [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug2:
> input_userauth_request: try method publickey [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug1: userauth_pubkey: test whether pkalg/pkblob are
> acceptable for ED25519 SHA256:+8vYuVEOth+7Ncxe/DYcPPBpvEwEwfPbr+qD2DKm3fY
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_key_allowed
> entering [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_send entering: type 22 [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug3: mm_key_allowed: waiting for MONITOR_ANS_KEYALLOWED
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_receive_expect entering: type 23 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug3: mm_request_receive entering [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug3: mm_request_receive entering Nov 12
> 13:45:17 sirius sshd[3241]: debug3: monitor_read: checking request 22 Nov
> 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed entering Nov 12
> 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed: key_from_blob:
> 0x558f44057060 Nov 12 13:45:17 sirius sshd[3241]: debug1:
> temporarily_use_uid: 200/200 (e=0/0) Nov 12 13:45:17 sirius sshd[3241]:
> debug1: trying public key file /usr/local/BackupPC/.ssh/authorized_keys Nov
> 12 13:45:17 sirius sshd[3241]: debug1: fd 4 clearing O_NONBLOCK Nov 12
> 13:45:17 sirius sshd[3241]: debug1: matching key found: file
> /usr/local/BackupPC/.ssh/authorized_keys, line 1 ED25519
> SHA256:+8vYuVEOth+7Ncxe/DYcPPBpvEwEwfPbr+qD2DKm3fY Nov 12 13:45:17 sirius
> sshd[3241]: debug1: restore_uid: 0/0
> Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed: key
> 0x558f44057060 is allowed Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_send entering: type 23 Nov 12 13:45:17 sirius sshd[3241]:
> debug3: send packet: type 60 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug2: userauth_pubkey: authenticated 0 pkalg ssh-ed25519 [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: Postponed publickey for backuppc from
> 192.168.8.3 port 39668 ssh2 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug3: receive packet: type 50 [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug1: userauth-request for user backuppc service
> ssh-connection method publickey [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug1: attempt 2 failures 0 [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug2: input_userauth_request: try method publickey [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: userauth_pubkey: test whether
> pkalg/pkblob are acceptable for RSA
> SHA256:07i2CAzyT2c3NHYQRlCT2bONAW8mIgJ7EVVkmLGzMuw [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: debug3: mm_key_allowed entering [preauth] Nov
> 12 13:45:17 sirius sshd[3241]: debug3: mm_request_send entering: type 22
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_key_allowed:
> waiting for MONITOR_ANS_KEYALLOWED [preauth] Nov 12 13:45:17 sirius
> sshd[3241]: debug3: mm_request_receive_expect entering: type 23 [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive entering
> [preauth] Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive
> entering Nov 12 13:45:17 sirius sshd[3241]: debug3: monitor_read: checking
> request 22 Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed
> entering Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed:
> key_from_blob: 0x558f44056f00 Nov 12 13:45:17 sirius sshd[3241]: debug1:
> temporarily_use_uid: 200/200 (e=0/0) Nov 12 13:45:17 sirius sshd[3241]:
> debug1: trying public key file /usr/local/BackupPC/.ssh/authorized_keys Nov
> 12 13:45:17 sirius sshd[3241]: debug1: fd 4 clearing O_NONBLOCK Nov 12
> 13:45:17 sirius sshd[3241]: debug2: user_key_allowed: check options:
> 'ssh-ed25519
> AAAAC3NzaC1lZDI1NTE5AAAAIKgBYt6r7yHGVoM2QFXFhtOdFrReyb2MycRgRdvpsFPr
> Generated on 181112.1124 for backuppc@sirius\n' Nov 12 13:45:17 sirius
> sshd[3241]: debug2: user_key_allowed: advance:
> 'AAAAC3NzaC1lZDI1NTE5AAAAIKgBYt6r7yHGVoM2QFXFhtOdFrReyb2MycRgRdvpsFPr
> Generated on 181112.1124 for backuppc@sirius\n' Nov 12 13:45:17 sirius
> sshd[3241]: debug1: matching key found: file
> /usr/local/BackupPC/.ssh/authorized_keys, line 2 RSA
> SHA256:07i2CAzyT2c3NHYQRlCT2bONAW8mIgJ7EVVkmLGzMuw Nov 12 13:45:17 sirius
> sshd[3241]: debug1: restore_uid: 0/0
> Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_answer_keyallowed: key
> 0x558f44056f00 is allowed Nov 12 13:45:17 sirius sshd[3241]: debug3:
> mm_request_send entering: type 23 Nov 12 13:45:17 sirius sshd[3241]:
> debug3: send packet: type 60 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> debug2: userauth_pubkey: authenticated 0 pkalg ssh-rsa [preauth] Nov 12
> 13:45:17 sirius sshd[3241]: Postponed publickey for backuppc from
> 192.168.8.3 port 39668 ssh2 [preauth] Nov 12 13:45:17 sirius sshd[3241]:
> Connection closed by 192.168.8.3 port 39668 [preauth] Nov 12 13:45:17
> sirius sshd[3241]: debug1: do_cleanup [preauth]
> Nov 12 13:45:17 sirius sshd[3241]: debug1: monitor_read_log: child log fd
> closed Nov 12 13:45:17 sirius sshd[3241]: debug3: mm_request_receive
> entering Nov 12 13:45:17 sirius sshd[3241]: debug1: do_cleanup
> Nov 12 13:45:17 sirius sshd[3241]: debug1: Killing privsep child 3242
> Nov 12 13:45:17 sirius sshd[3241]: debug1: audit_event: unhandled event 12
> root@sirius/etc/ssh #
> 
> Alan

Does your user without ssh access use a dsa key? In that case a rsa key should 
be used/generated.

-- 
vr.gr.

Freek de Kruijf