Hi Everybody,
Recently i applied patch cluster dated (2009.11.03) for solaris 10 sparc machine(Generic_138888-06)
I successfully applied and rebooted the machine , no errors received. But after patching it was not allowing me to login through ssh while telnet was working fine.Logs showed me
sshd[11712]: [ID 800047 auth.crit] fatal: matching cipher is not supported: aes256-ctr
i checked sshd_config but the following line containing ciphers was commented.
Ciphers aes128-ctr,aes128-cbc,arcfour,3des-cbc,blowfish-cbc
i need to uncomment the line and restart the ssh service to allow ssh login.
now ssh version is Sun_SSH_1.1.2, previously it was Sun_SSH_1.1 though i didn't notice any patch related to ssh in cluster.
Can anybody please help me know if we have any other solution for this? Can we remove a particular patch and then no need to modify sshd_config file?
output please..
#svcs ssh
#ssh -lvv <username>@localhost
Thanks incredible
1st o/p is online 2:57:29 svc:/network/ssh:default
2nd --able to connect through ssh -lvv user@localhost
but when i tried through putty its not allowing.
Thanks solaris user
discussion is quite useful.I may need to install SUNWcry package and try for the patch.
Thanks again i'll try these.
which user did you try to ssh as, from the remote host? is it root or normal user?
I tried ssh login as normal user from remote host to this host and it worked fine but from putty it is not allowing.
you lauching putty from the same VLAN? if not, there will be problem. Is this the first time you trying this? As long as you can ssh to the destination server from anywhere, the problem cannot be at the destination, but from the source. When you launch putty with the IP, you should see the "login" message first. Did you get that at least?
Yes, i'm working in the same VLAN so that is not the problem. I received the same ssh login problem for other server also, which was also at the same patch level as this server and when i patched that.
Checked the syslog and found same error: fatal: matching cipher is not supported: aes256-ctr
Uncommenting the line containing ciphers and restarting the ssh service, made it work.
Not sure if youve resolved this yet. On solaris 10 releases prior to 10/08 installation there is no SUNWcry package (crypt). Once you update to kernel rev 139555-08 this problem will surface.
---------------------
Try pkginfo -l | grep SUNWcry
also check if patch 141742-02 is installed ( showrev -p | grep 141742-02 )
---------------------
if you do not have SUNWcry and DO have the above patch installed, pop a sol 10 10/08 CD/DVD and do a pkgadd of SUNWcry, then, remove and re-add 141742-02. Problem should disappear.
Newer releases of Sol10 came with SUNWcry so are no issue.
All above is based on SPARC, so if using opensolaris, or i386 sol10, you'll need to research the pacth number (same issue exists, but diff patch rev between arch).
Quick n nasty workarounds:
1 - if using putty, when opening a new session, go to the ssh section, and in the box titled "Encryption selection cipher" move blowfish to the top and try again.
2 - server side workaround:
Change the two config files /etc/ssh/ssh_config and /etc/ssh/sshd_config and add the following line:
Ciphers aes128-ctr,aes128-cbc,arcfour,3des-cbc,blowfish-cbc
then restart ssh
FYI, obviously by implementing the server side workaround,
you are leaving your system in a weaker state as far as
encyption goes.
CAVEAT: Make sure you read the pacth install instructions - can't
remember if it requires a reboot when removing/re-adding the patch.
Hi... when you apply the patch, is it need to boot to single mode?
As my caveat states, make sure you read the patch install instructions. Can't just give you all the answers 
Having said that, SUN always recommend to install patches in single user mode. Sometimes that's not so practical, and I've generally applied patches running in multiuser with no issues esp if it's not a kernel patch.
If it goes wrong though, you wear it, because you didn't follow SUN's advice.
Cheers,
That is always the recommended method.