labgrid-project / labgrid-project/labgrid

NetworkService: Password Authentication not preferred when connecting via Proxy

Open
#929 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

needs author info
Dominant language
Python
Stars
528
Forks
278
Avg merge
2d 19h
Merged PRs (30d)
4

Description

Hi,

I have a target which is only reachable by using Labgrids Proxy-Mechanism, or (obviously) by logging into the host which connects to the target and which runs the exporter.

The target only supports password authentication.

I faced the following issue: When setting MaxAuthTries 1 in the targets sshd_config (or when having >= than MaxAuthTries' ssh identitys), I am no longer able to connect to the target via the Proxy. The direct connection (labgrid-client on the exporter host) still works fine.

To be honest, I don't know what causes this. A wild guess is its related to the environment (SSH_ASKPASS_REQUIRE) not being available on the Jump host.

A workaround is adding something like this in SSHDriver._start_own_master_once:

        if self.networkservice.password:
            args += ["-o", 'PreferredAuthentications="password"']

Here is a log with ssh's loglevel set to debug and an additional log of the full ssh command labgrid builds:

$ labgrid-client -p slot2 ssh --name eth
WARNING: RUN: ['ssh', '-f', '-o', 'LogLevel=DEBUG', '-x', '-o', 'ConnectTimeout=30', '-o', 'ControlPersist=300', '-o', 'UserKnownHostsFile=/dev/null', '-o', 'StrictHostKeyChecking=no', '-o', 'ServerAliveInterval=15', '-MN', '-S', '/tmp/labgrid-ssh-tmp-pq_s64tp/control-169.254.21.34', '-p', '22', '-l', 'root', '169.254.21.34', '-o', 'ProxyCommand=ssh -x -o LogLevel=DEBUG -o PasswordAuthentication=no -o ControlMaster=no -o ControlPath=/tmp/labgrid-connection-vce7pg2x/control-exporter exporter -W 169.254.21.34:22 2>/tmp/labgrid-ssh-tmp-pq_s64tp/proxy-stderr']
WARNING: ssh: debug1: Reading configuration data /home/devel/.ssh/config
WARNING: ssh: debug1: Reading configuration data /etc/ssh/ssh_config
WARNING: ssh: debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
WARNING: ssh: debug1: /etc/ssh/ssh_config line 21: Applying options for *
WARNING: ssh: debug1: Executing proxy command: exec ssh -x -o LogLevel=DEBUG -o PasswordAuthentication=no -o ControlMaster=no -o ControlPath=/tmp/labgrid-connection-vce7pg2x/control-exporter exporter -W 169.254.21.34:22 2>/tmp/labgrid-ssh-tmp-pq_s64tp/proxy-stderr
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_rsa type 0
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_rsa-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_dsa type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_dsa-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ecdsa type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ecdsa-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ecdsa_sk type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ecdsa_sk-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ed25519 type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ed25519-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ed25519_sk type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_ed25519_sk-cert type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_xmss type -1
WARNING: ssh: debug1: identity file /home/devel/.ssh/id_xmss-cert type -1
WARNING: ssh: debug1: Local version string SSH-2.0-OpenSSH_8.4p1 Ubuntu-6ubuntu2.1
WARNING: ssh: debug1: Remote protocol version 2.0, remote software version OpenSSH_7.1
WARNING: ssh: debug1: match: OpenSSH_7.1 pat OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.4*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* compat 0x04000002
WARNING: ssh: debug1: Authenticating to 169.254.21.34:22 as 'root'
WARNING: ssh: debug1: SSH2_MSG_KEXINIT sent
WARNING: ssh: debug1: SSH2_MSG_KEXINIT received
WARNING: ssh: debug1: kex: algorithm: curve25519-sha256@libssh.org
WARNING: ssh: debug1: kex: host key algorithm: ecdsa-sha2-nistp256
WARNING: ssh: debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
WARNING: ssh: debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
WARNING: ssh: debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
WARNING: ssh: debug1: Server host key: ecdsa-sha2-nistp256 SHA256:o6d6Bgm/lbi0vNqqY3V2uya9GAOmN/5QHLr5CT4iKlA
WARNING: ssh: Warning: Permanently added '169.254.21.34' (ECDSA) to the list of known hosts.
WARNING: ssh: debug1: rekey out after 134217728 blocks
WARNING: ssh: debug1: SSH2_MSG_NEWKEYS sent
WARNING: ssh: debug1: expecting SSH2_MSG_NEWKEYS
WARNING: ssh: debug1: SSH2_MSG_NEWKEYS received
WARNING: ssh: debug1: rekey in after 134217728 blocks
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_rsa RSA SHA256:5KzmBzkhR/M1m3XEZ8npxZxgPRWGn8YTeKbhPE9bA34
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_dsa
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_ecdsa
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_ecdsa_sk
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_ed25519
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_ed25519_sk
WARNING: ssh: debug1: Will attempt key: /home/devel/.ssh/id_xmss
WARNING: ssh: debug1: SSH2_MSG_SERVICE_ACCEPT received
WARNING: ssh: debug1: Authentications that can continue: publickey,password
WARNING: ssh: debug1: Next authentication method: publickey
WARNING: ssh: debug1: Offering public key: /home/devel/.ssh/id_rsa RSA SHA256:5KzmBzkhR/M1m3XEZ8npxZxgPRWGn8YTeKbhPE9bA34
WARNING: ssh: Received disconnect from UNKNOWN port 65535:2: Too many authentication failures
WARNING: ssh: Disconnected from UNKNOWN port 65535

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in SSHDriver._start_own_master_once and compare the SSH command built for direct connections with the ProxyCommand shown in the report. Reproduce with labgrid-client -p slot2 ssh --name eth and a target limited to password authentication; done means password authentication is preferred through the proxy without exhausting the target's authentication attempts.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
networking
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.