X2Go Bug report logs - #368
GSSAPI support falls back to SSH key

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Fri, 13 Dec 2013 11:18:01 UTC

Severity: normal

Found in version 4.0.1.2-pre03

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to x2go-dev@lists.berlios.de, X2Go Developers <x2go-dev@lists.berlios.de>:
Bug#368; Package x2goclient. (Fri, 13 Dec 2013 11:18:01 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mike Gabriel <mike.gabriel@das-netzwerkteam.de>:
New Bug report received and forwarded. Copy sent to X2Go Developers <x2go-dev@lists.berlios.de>. (Fri, 13 Dec 2013 11:18:01 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.x2go.org (full text, mbox):

From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: "submit@bugs.x2go.org" <submit@bugs.x2go.org>
Subject: GSSAPI support falls back to SSH key
Date: Fri, 13 Dec 2013 11:17:18 +0000
[Message part 1 (text/plain, inline)]
Package: x2goclient
Version: 4.0.1.2-pre03

Hi Alex,

with the latest GSSAPI patch in X2Go Client, I observe the following:

Session profile options:

autologin = false
krblogin = true

If GSSAPI fails, the underlying ssh process falls back to SSH-key  
based authentication. When this happens on passphrase protected SSH  
keys, I see this when running X2Go Client from the command line:

"""
mike@<host>:~$ LANG=C x2goclient
x2go-INFO-1> "Starting x2goclient..."
x2go-WARNING-1> "Can't load translator: :/x2goclient_c"
x2go-WARNING-2> "Can't load translator: :/qt_C"
x2go-INFO-3> "Started  x2goclient."
x2go-INFO-8> "Starting connection to server: fylgja.das-netzwerkteam.de:32032"
Enter passphrase for key '/home/mike/.ssh/id_rsa':
"""
      ^^^^^^^^^^^^^^^^^^

At this point X2Go Client waits for the input and only continues with  
SSH key based authentication then (although autologin has been set to  
false!).

Seems like you should limit the ssh subprocess execution to  
GSSAPIAuthentication only and disable all other auth methods (unless  
autologin is true).

Mike
-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Wed Dec 12 05:15:13 2018; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.