Le 2023-08-14 00:04, Cameron Simpson a écrit :
On 13Aug2023 23:23, François Patte
<francois.patte@xxxxxxxxxxxxxxxxxxxx> wrote:
Since I upgraded to f38 it is impossible to connect to a machine using
ssh rsa-key....
the file .ssh/authorized_keys has not change, but any remote
connection to this machine asks for a password....
More likely you're not offering the RSA key any more or the remote
isn't accepting it. Run "ssh -v" to see what's happening. Here's some
example output from a run here:
[...]
debug1: Will attempt key: /home/cameron/.ssh/id_ecdsa ECDSA
SHA256:********************* agent
<couic>
Here is the part I get with ssh -v:
debug1: Next authentication method: publickey
debug1: Offering public key: /home/patte/.ssh/id_rsa RSA SHA256:
**************************
debug1: Authentications that can continue:
publickey,gssapi-keyex,gssapi-with-mic,password
debug1: Trying private key: /home/patte/.ssh/id_dsa
debug1: Trying private key: /home/patte/.ssh/id_ecdsa
debug1: Trying private key: /home/patte/.ssh/id_ecdsa_sk
debug1: Trying private key: /home/patte/.ssh/id_ed25519
debug1: Trying private key: /home/patte/.ssh/id_ed25519_sk
debug1: Trying private key: /home/patte/.ssh/id_xmss
I suspect some ssh configuration has changed with the upgrade,
possibly in /etc/ssh/ssh_config. Certainly some key types (or smaller
sizes) fall out of favour as they become inadequately secure.
Where will it be mentionned? I have this in the /etc/ssh/ssh_config
file:
#HostKey /etc/ssh/ssh_host_rsa_key
#HostKey /etc/ssh/ssh_host_ecdsa_key
#HostKey /etc/ssh/ssh_host_ed25519_key
Thank you for helping.
--
François Patte
UFR de mathématiques et informatique
Laboratoire CNRS MAP5, UMR 8145
Université Paris Descartes
45, rue des Saints Pères
F-75270 Paris Cedex 06
Tél. +33 (0)6 7892 5822
http://www.math-info.univ-paris5.fr/~patte
FSF
https://www.fsf.org/blogs/community/presenting-shoetool-happy-holidays-from-the-fsf
_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue