View unanswered posts    View active topics

All times are UTC - 6 hours





Post new topic Reply to topic  [ 8 posts ] 
Print view Previous topic   Next topic  
Author Message
Search for:
 Post subject: Cannot SSH after upgrade
PostPosted: Sat Aug 11, 2007 9:23 am 
Offline
Joined: Sun Dec 04, 2005 1:44 pm
Posts: 403
Location: Central NJ
I just upgraded to R5F1. Now, when I try to SSH from another box on my network, I can connect, but when I try to login as root, my password keeps failing.

If I log locally to my myth box as root, the same password works. I don't know what could be happening here.

_________________
Currently running: R5.5, HD5000 x 2, PVR150, Athlon 64 3000+, Chaintech VNF4, 1GB RAM, 2 x 250GB in LVM, MSI NX6200TC -> AA 9A60 -> HDTV


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 11, 2007 9:30 am 
Offline
Joined: Mon Apr 17, 2006 2:52 pm
Posts: 31
Location: Michigan
It is set that way purposely in R5F1.

You can log in as another account and SU if you need root access.


From "The Guide"

Quote:
6) Remote access changes:

6.1) For improved security, direct ssh access as the "mythtv" and "root" users and for users with blank passwords has been disabled in /etc/ssh/sshd_config. For ssh access as root you must login as user created during phase 1 installation, run "su - root", and provide the root password.

_________________
Increasing my couch potatoness by a factor of pie.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 11, 2007 9:38 am 
Offline
Joined: Sun Dec 04, 2005 1:44 pm
Posts: 403
Location: Central NJ
OK, I understand the security benefits of enforcing that. I just didn't realize it was implemented.

Is there a place to change this default?

_________________
Currently running: R5.5, HD5000 x 2, PVR150, Athlon 64 3000+, Chaintech VNF4, 1GB RAM, 2 x 250GB in LVM, MSI NX6200TC -> AA 9A60 -> HDTV


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 11, 2007 9:40 am 
Offline
Joined: Mon Apr 17, 2006 2:52 pm
Posts: 31
Location: Michigan
It is set that way purposely in R5F1.

You can log in as another account and SU if you need root access.


From "The Guide"

Quote:
6) Remote access changes:

6.1) For improved security, direct ssh access as the "mythtv" and "root" users and for users with blank passwords has been disabled in /etc/ssh/sshd_config. For ssh access as root you must login as user created during phase 1 installation, run "su - root", and provide the root password.

_________________
Increasing my couch potatoness by a factor of pie.


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 11, 2007 11:19 am 
Offline
Joined: Thu Mar 25, 2004 11:00 am
Posts: 9551
Location: Arlington, MA
It's generally a good idea to provide a link to the R5F1 hints. That way at least some folks take the clue and read the rest of it... ;-)


Top
 Profile  
 
 Post subject:
PostPosted: Sat Aug 11, 2007 3:58 pm 
Offline
Joined: Mon Apr 17, 2006 2:52 pm
Posts: 31
Location: Michigan
tjc wrote:
It's generally a good idea to provide a link to the R5F1 hints. That way at least some folks take the clue and read the rest of it... ;-)


Yup

The Guide

_________________
Increasing my couch potatoness by a factor of pie.


Top
 Profile  
 
PostPosted: Thu Aug 16, 2007 6:34 pm 
Offline
Joined: Mon Nov 07, 2005 10:09 am
Posts: 153
Previously, I used a script that would use id_rsa.pub from the master backend server user mythtv put into authorized_keys of mythtv on my slave backend server.

The key-gen -t rsa i created was a a blank password. this allowed me to issue the command ssh mythtv@mythtvslave /etc/init.d/mythtv-backend start
from the master backend.

I used this command at the end of /etc/init.d/bootmisc.sh to automatically restart the tuners on the slaves after a master reboot and after a mythbackup.

This was extremely useful.

I would like a secure way to do this.

Any ideas.

I could do it as another user but the sudoers stuff is confusing to me right now.
Also, wouldn't this be a very useful feature for others with a slave setup?

I will try to undo the changes listed above, but maybe that isn't the best longtime solution


Top
 Profile  
 
 Post subject:
PostPosted: Thu Aug 16, 2007 6:57 pm 
Offline
Joined: Thu Mar 25, 2004 11:00 am
Posts: 9551
Location: Arlington, MA
Undoing the change is literally a matter of deleting or commenting out one very obvious line in the file noted, and restarting sshd. It's not rocket science.


Top
 Profile  
 

Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 


All times are UTC - 6 hours




Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group

Theme Created By ceyhansuyu