{"id":273,"date":"2009-03-25T21:18:37","date_gmt":"2009-03-26T03:18:37","guid":{"rendered":"http:\/\/vostorga.org\/?p=273"},"modified":"2009-03-25T21:18:37","modified_gmt":"2009-03-26T03:18:37","slug":"openssh-y-configuracion-de-dns","status":"publish","type":"post","link":"https:\/\/vostorga.org\/?p=273","title":{"rendered":"OpenSSH y configuraci\u00f3n de DNS"},"content":{"rendered":"<p>Recientemente me fij\u00e9 que un Linux Box tardaba demasiado tiempo (unos 6 segundos) para pedirme la contrase\u00f1a una vez ingresado el comando <em>ssh user@ip<\/em><\/p>\n<p>Haciendo una depuraci\u00f3n del lado del cliente, se mostraba lo siguiente:<\/p>\n<blockquote><p>debug2: set_newkeys: mode 1<br \/>\ndebug1: SSH2_MSG_NEWKEYS sent<br \/>\ndebug1: expecting SSH2_MSG_NEWKEYS<br \/>\ndebug2: set_newkeys: mode 0<br \/>\ndebug1: SSH2_MSG_NEWKEYS received<br \/>\ndebug1: SSH2_MSG_SERVICE_REQUEST sent<br \/>\ndebug2: service_accept: ssh-userauth<br \/>\ndebug1: SSH2_MSG_SERVICE_ACCEPT received<br \/>\ndebug2: key: \/home\/vostorga\/.ssh\/id_rsa<br \/>\ndebug2: key: \/home\/vostorga\/.ssh\/id_dsa<\/p>\n<p>&lt;una pausa de 6 segundos&gt;<\/p>\n<p>debug1: Authentications that can continue: publickey,password<br \/>\ndebug1: Next authentication method: publickey<br \/>\ndebug1: Offering public key: \/home\/vostorga\/.ssh\/id_rsa<br \/>\ndebug2: we sent a publickey packet, wait for reply<br \/>\ndebug1: Authentications that can continue: publickey,password<br \/>\ndebug1: Trying private key: \/home\/vostorga\/.ssh\/id_dsa<br \/>\ndebug2: we did not send a packet, disable method<br \/>\ndebug1: Next authentication method: password<br \/>\nroot@192.168.x.x&#8217;s password:<\/p><\/blockquote>\n<p>Al principio pens\u00e9 que hab\u00eda alg\u00fan problema con los tipos de autenticaci\u00f3n disponibles en el servidor, pero viendo un problema parecido del joven <a href=\"http:\/\/jmaslibre.wordpress.com\/\" target=\"_blank\">jmaslibre<\/a> con su DNS, me puse a revisar la configuraci\u00f3n de dns del servidor OpenSSH, en otras palabras \/etc\/hosts y \/etc\/resolv.conf y result\u00f3 que la IP especificada en \/etc\/resolv.conf no\u00a0 estaba ofreciendo DNS.<\/p>\n<p>Lo curioso es que si no se especificaba servidor DNS o se agregaba otro, funcionaba correctamente, a pesar de estar trabajando en una LAN.<\/p>\n<p>El servidor OpenSSH quer\u00eda hacer una resoluci\u00f3n inversa y esos segundos de pausa era el intento fallido de realizar dicha operaci\u00f3n, por lo que las soluciones pueden incluir:<\/p>\n<ul>\n<li>Verificar \/etc\/hosts<\/li>\n<li>Verificar que \/etc\/resolv.conf no contengan servidores inv\u00e1lidos<\/li>\n<li>Deshabilitar en el archivo <em>sshd_config<\/em> la resoluci\u00f3n inversa con el par\u00e1metro <em>UseDNS no<\/em><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Recientemente me fij\u00e9 que un Linux Box tardaba demasiado tiempo (unos 6 segundos) para pedirme la contrase\u00f1a una vez ingresado el comando ssh user@ip Haciendo una depuraci\u00f3n del lado del cliente, se mostraba lo siguiente: debug2: set_newkeys: mode 1 debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug2: set_newkeys: mode 0 debug1: SSH2_MSG_NEWKEYS received debug1: SSH2_MSG_SERVICE_REQUEST sent [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[85,6,100],"class_list":["post-273","post","type-post","status-publish","format-standard","hentry","category-linux","tag-dns","tag-ssh","tag-ssh2_msg_service_accept"],"_links":{"self":[{"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/posts\/273"}],"collection":[{"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vostorga.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=273"}],"version-history":[{"count":4,"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/posts\/273\/revisions"}],"predecessor-version":[{"id":277,"href":"https:\/\/vostorga.org\/index.php?rest_route=\/wp\/v2\/posts\/273\/revisions\/277"}],"wp:attachment":[{"href":"https:\/\/vostorga.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vostorga.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vostorga.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}