X2Go Bug report logs - #734
ssh-agent gets used although GSSAPI is enabled and agent-auth is disabled

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Sat, 10 Jan 2015 00:20:02 UTC

Severity: important

Found in version 4.0.3.1

Fix blocked by 733: SSH GSSAPI: use master+slave sockets

Full log


Message #7 received at submit@bugs.x2go.org (full text, mbox, reply):

Received: (at submit) by bugs.x2go.org; 10 Jan 2015 00:16:10 +0000
From mike.gabriel@das-netzwerkteam.de  Sat Jan 10 01:16:04 2015
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 3CF385DEAA
	for <submit@bugs.x2go.org>; Sat, 10 Jan 2015 01:16:04 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id C38723221
	for <submit@bugs.x2go.org>; Sat, 10 Jan 2015 01:16:03 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 577FD3C841
	for <submit@bugs.x2go.org>; Sat, 10 Jan 2015 01:16:03 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 2dBVQ1ripacU for <submit@bugs.x2go.org>;
	Sat, 10 Jan 2015 01:16:03 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 16E873C7AB
	for <submit@bugs.x2go.org>; Sat, 10 Jan 2015 01:16:03 +0100 (CET)
Received: from bifrost.das-netzwerkteam.de (bifrost.das-netzwerkteam.de
 [178.62.101.154]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Sat, 10 Jan 2015 00:16:03 +0000
Date: Sat, 10 Jan 2015 00:16:03 +0000
Message-ID: <20150110001603.Horde.RZlmXfUQgaeCAysehUiZAg1@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: submit@bugs.x2go.org
Subject: ssh-agent gets used although GSSAPI is enabled and agent-auth is
 disabled
User-Agent: Internet Messaging Program (IMP) H5 (6.2.2)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 178.62.101.154
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101
 Firefox/32.0 Iceweasel/32.0
Content-Type: multipart/signed; boundary="=_ZI207iYB578XC0gbl5eTHw1";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
Package: x2goclient
Version: 4.0.3.1
Severity: important
Control: block -1 by 733

I have...

autologin=false
krblogin=true

_plus_ a running ssh-agent, loaded with my private SSH key.

The X2Go Server has the public SSH key belonging to the private key  
loaded into the agent.

If the remote server does not support GSSAPIauthentication (set to  
"no" via sshd_config), then X2Go Client should fall back to  
username+password (KbdInteractiveAuthentication).

At the time of writing this, X2Go Client nonetheless uses the running  
ssh-agent and performs a PubkeyAuthentication.

However, this breaks GSSAPI credentials delegation...

Mike

-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Sun Jan 29 08:56:07 2023; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.