Hi,
I have a hopefully simple problem - I've had success getting moonshot to work using gss-client and
gss-server between two different Scientific Linux 6 hosts, using a third system based on the live
DVD as the IdP, but at the moment ssh between the same pair of boxes is not working (possibly
because I simply don't have the correctly patched version of openssh, or have failed to do something
elementary).
By looking at the debug output from freeradius I can see that authentication is succeeding and the
SAML headers are going out, but it's at this point that it apparently fails. I'm currently using a
sshd built from the git repository, and the relevant part of the debug output looks like:
debug1: userauth-request for user moonshot service ssh-connection method gssapi-with-mic
debug1: attempt 1 failures 0
debug2: input_userauth_request: try method gssapi-with-mic
Postponed gssapi-with-mic for invalid user moonshot from 192.168.122.92 port 60699 ssh2
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: Got no client credentials
debug1: No suitable client data
Failed gssapi-with-mic for invalid user moonshot from 192.168.122.92 port 60699 ssh2
On the other hand the same output when ssh'ing into the live DVD system (which _does_ work from the
SL6 client) ends with:
...
debug1: Got no client credentials
debug1: Got no client credentials
debug1: userok succeded for moonshot
debug1: do_pam_account: called
debug3: PAM: do_pam_account pam_acct_mgmt = 0 (Success)
Accepted gssapi-with-mic for moonshot from 192.168.122.92 port 53376 ssh2
I've already made sure that /etc/shibboleth/attribute-map.xml on the SSH server contains
<Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" id="local-login-user"/>
Would be grateful for any suggestions!
Best regards,
Stuart
--
Dr. Stuart Rankin
Senior System Administrator
High Performance Computing Service
University of Cambridge
Email: [log in to unmask]
Tel: (+)44 1223 763517
|