X-Recipient: archive-cygwin AT delorie DOT com X-SWARE-Spam-Status: No, hits=-1.7 required=5.0 tests=AWL,BAYES_00 X-Spam-Check-By: sourceware.org Date: Wed, 02 Sep 2009 14:08:06 -0700 To: cygwin AT cygwin DOT com From: jeffunit Subject: Re: ssh and sftp connects intermittently In-Reply-To: <4A9EDD64.8090708@cygwin.com> References: <1251918865 DOT 25462 DOT ezmlm AT cygwin DOT com> <20090902192852438 DOT EHES29089 AT cdptpa-omta03 DOT mail DOT rr DOT com> <4A9ECA81 DOT 3040600 AT cygwin DOT com> <20090902195353031 DOT QFQB8054 AT cdptpa-omta01 DOT mail DOT rr DOT com> <4A9ED1DC DOT 8090809 AT cygwin DOT com> <20090902203018853 DOT GVRP16127 AT cdptpa-omta02 DOT mail DOT rr DOT com> <4A9EDD64 DOT 8090708 AT cygwin DOT com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed Message-Id: <20090902210809413.TNZO8054@cdptpa-omta01.mail.rr.com> X-IsSubscribed: yes Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com At 02:02 PM 9/2/2009, you wrote: >On 09/02/2009 04:30 PM, jeffunit wrote: >>As I said, the problem is intermittent. However, once I have the problem, >>it occurs reliably. Here is some verbose output, which isn't very >>helpful... > >Perhaps. I find this interesting though. > >>U:\>sftp -v -v -v jdeifik AT www DOT weasel DOT com >>Connecting to www.weasel.com... >>OpenSSH_5.1p1, OpenSSL 0.9.8k 25 Mar 2009 >>debug2: ssh_connect: needpriv 0 >>debug1: Connecting to www.weasel.com [208.97.189.139] port 22. > >If I do the same thing, though I'm in bash, I get this line first: > >debug1: Reading configuration data /etc/ssh_config > >>I have to use control-C to stop this, as it hangs after the 'connecting >>to' line. >> >>This problem is independent of where I am connecting to. > >Really. So you could debug on the server side then and see if there's >any interaction. If not, it sounds like this is a problem with an >outgoing firewall block or other BLODA . Here is some output when run with bash. The first output successfully connects, the second one hangs. Since this issue is intermittent, I suspect it might not be a BLODA issue... phenomii:/cygdrive/u:501: ssh -v -v -v jdeifik AT www DOT weasel DOT com OpenSSH_5.1p1, OpenSSL 0.9.8k 25 Mar 2009 debug2: ssh_connect: needpriv 0 debug1: Connecting to www.weasel.com [208.97.189.139] port 22. debug1: Connection established. debug1: identity file /home/jdeifik/.ssh/identity type -1 debug1: identity file /home/jdeifik/.ssh/id_rsa type -1 debug1: identity file /home/jdeifik/.ssh/id_dsa type -1 debug1: Remote protocol version 2.0, remote software version OpenSSH_5.1p1 debug1: match: OpenSSH_5.1p1 pat OpenSSH* debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_5.1 debug2: fd 3 setting O_NONBLOCK debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman- roup-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 debug2: kex_parse_kexinit: ssh-rsa,ssh-dss debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc AT lysator DOT liu DOT se,aes128- tr,aes192-ctr,aes256-ctr debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc AT lysator DOT liu DOT se,aes128- tr,aes192-ctr,aes256-ctr debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64 AT openssh DOT com,hmac-ripemd16 ,hmac-ripemd160 AT openssh DOT com,hmac-sha1-96,hmac-md5-96 debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64 AT openssh DOT com,hmac-ripemd16 ,hmac-ripemd160 AT openssh DOT com,hmac-sha1-96,hmac-md5-96 debug2: kex_parse_kexinit: none,zlib AT openssh DOT com,zlib debug2: kex_parse_kexinit: none,zlib AT openssh DOT com,zlib debug2: kex_parse_kexinit: debug2: kex_parse_kexinit: debug2: kex_parse_kexinit: first_kex_follows 0 debug2: kex_parse_kexinit: reserved 0 debug2: kex_parse_kexinit: diffie-hellman-group-exchange-sha256,diffie-hellman- roup-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 debug2: kex_parse_kexinit: ssh-rsa,ssh-dss debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc AT lysator DOT liu DOT se,aes128- tr,aes192-ctr,aes256-ctr debug2: kex_parse_kexinit: aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour 28,arcfour256,arcfour,aes192-cbc,aes256-cbc,rijndael-cbc AT lysator DOT liu DOT se,aes128- tr,aes192-ctr,aes256-ctr debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64 AT openssh DOT com,hmac-ripemd16 ,hmac-ripemd160 AT openssh DOT com,hmac-sha1-96,hmac-md5-96 debug2: kex_parse_kexinit: hmac-md5,hmac-sha1,umac-64 AT openssh DOT com,hmac-ripemd16 ,hmac-ripemd160 AT openssh DOT com,hmac-sha1-96,hmac-md5-96 debug2: kex_parse_kexinit: none,zlib AT openssh DOT com debug2: kex_parse_kexinit: none,zlib AT openssh DOT com debug2: kex_parse_kexinit: debug2: kex_parse_kexinit: debug2: kex_parse_kexinit: first_kex_follows 0 debug2: kex_parse_kexinit: reserved 0 debug2: mac_setup: found hmac-md5 debug1: kex: server->client aes128-cbc hmac-md5 none debug2: mac_setup: found hmac-md5 debug1: kex: client->server aes128-cbc hmac-md5 none debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP debug2: dh_gen_key: priv key bits set: 124/256 debug2: bits set: 473/1024 debug1: SSH2_MSG_KEX_DH_GEX_INIT sent debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY debug3: check_host_in_hostfile: filename /home/jdeifik/.ssh/known_hosts debug3: check_host_in_hostfile: match line 2 debug3: check_host_in_hostfile: filename /home/jdeifik/.ssh/known_hosts debug3: check_host_in_hostfile: match line 2 debug1: Host 'www.weasel.com' is known and matches the RSA host key. debug1: Found key in /home/jdeifik/.ssh/known_hosts:2 debug2: bits set: 529/1024 debug1: ssh_rsa_verify: signature correct debug2: kex_derive_keys debug2: set_newkeys: mode 1 debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug2: set_newkeys: mode 0 debug1: SSH2_MSG_NEWKEYS received debug1: SSH2_MSG_SERVICE_REQUEST sent debug2: service_accept: ssh-userauth debug1: SSH2_MSG_SERVICE_ACCEPT received debug2: key: /home/jdeifik/.ssh/identity (0x0) debug2: key: /home/jdeifik/.ssh/id_rsa (0x0) debug2: key: /home/jdeifik/.ssh/id_dsa (0x0) debug1: Authentications that can continue: publickey,password,keyboard-interact ve debug3: start over, passed a different list publickey,password,keyboard-interac ive debug3: preferred publickey,keyboard-interactive,password debug3: authmethod_lookup publickey debug3: remaining preferred: keyboard-interactive,password debug3: authmethod_is_enabled publickey debug1: Next authentication method: publickey debug1: Trying private key: /home/jdeifik/.ssh/identity debug3: no such identity: /home/jdeifik/.ssh/identity debug1: Trying private key: /home/jdeifik/.ssh/id_rsa debug3: no such identity: /home/jdeifik/.ssh/id_rsa debug1: Trying private key: /home/jdeifik/.ssh/id_dsa debug3: no such identity: /home/jdeifik/.ssh/id_dsa debug2: we did not send a packet, disable method debug3: authmethod_lookup keyboard-interactive debug3: remaining preferred: password debug3: authmethod_is_enabled keyboard-interactive debug1: Next authentication method: keyboard-interactive debug2: userauth_kbdint debug2: we sent a keyboard-interactive packet, wait for reply debug2: input_userauth_info_req debug2: input_userauth_info_req: num_prompts 1 Password: debug3: packet_send2: adding 32 (len 14 padlen 18 extra_pad 64) phenomii:/cygdrive/u:502: ssh -v -v -v jdeifik AT www DOT weasel DOT com OpenSSH_5.1p1, OpenSSL 0.9.8k 25 Mar 2009 debug2: ssh_connect: needpriv 0 debug1: Connecting to www.weasel.com [208.97.189.139] port 22. I had to use control-C to stop this, as it has been hanging at this point for 5 minutes. jeff -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple