Discussion:
Exact "Accepted password for" log message meaning
(too old to reply)
Daniel Llewellyn
2011-01-19 21:31:44 UTC
Permalink
And again, to the list.
Dec 30 09:18:23 host1 sshd[2281638]: Connection from 10.0.0.1 port 1217
Dec 30 09:18:29 host1 sshd[2281638]: Failed none for XXX from 10.0.0.1 port 1217
ssh2
Dec 30 09:18:33 host1 sshd[2281638]: Accepted password for XXX from 10.0.0.1
port 1217 ssh2
Dec 30 09:18:33 host1 sshd[1908826]: Disconnecting: Remote login for account XXX
is not allowed.
- the 3rd line does not say that connection is OK
- the 3rd line only means that the password method is allowed on this server to
connect ?
as far as I'm aware: "Accepted password for XXX" means that user "XXX"
has correctly authenticated with SSH's password mechanism. The next
line after that informs that XXX, while correctly AUTHENTICATING, is
not AUTHORISED to use the service.

caveat: I notice that the PIDs (2281638 and 1908826) are different
from the first three lines and the fourth. Are you sure these four
lines all refer to the same connection attempt?

--
Regards,
The Honeymonster aka Daniel Llewellyn
Raymond A. Meijer
2011-01-21 06:53:30 UTC
Permalink
For the different pids, it is hard for me to say ... a process child ?
Yes, I think it's because of SSH's Privilege Separation feature that a
new child process is started.


Ray

--
Raymond A. Meijer
You cannot discover new oceans
unless you have the courage to
lose sight of the shore

Loading...