{"id":2066,"date":"2022-11-23T09:04:48","date_gmt":"2022-11-23T08:04:48","guid":{"rendered":"https:\/\/www.dirk-hagedorn.de\/?p=2066"},"modified":"2022-11-23T09:04:48","modified_gmt":"2022-11-23T08:04:48","slug":"kurztipp-no-matching-host-key-type-found","status":"publish","type":"post","link":"https:\/\/www.dirk-hagedorn.de\/?p=2066","title":{"rendered":"Kurztipp: no matching host key type found"},"content":{"rendered":"<p>Nach dem Upgrade auf Ubuntu 22.04. scheitert erneut der Zugriff per ssh auf eine VM mit einem Uralt-SCO-Unix, in diesem Falle mit folgender Fehlermeldung:<\/p>\n<pre>$ ssh vmsco\r\nUnable to negotiate with 192.168.47.11 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss\r\nlost connection\r\n<\/pre>\n<p>Warum auch immer (bestimmt aus Sicherheitsgr\u00fcnden) \u00fcbermittelt ssh den id_dsa.pub nicht mehr an den SSH-Server. Abhilfe:<\/p>\n<p>Beim einmaligen Zugriff erweitert man den Aufruf von ssh\/scp um eine Option:<\/p>\n<pre>$ ssh -oHostKeyAlgorithms=+ssh-dss vmsco\r\n<\/pre>\n<p>Um die Option dauerhaft zu setzen, packe man diese in die globale SSH-Konfiguration f\u00fcr den Namen und die IP-Adresse des SSH-Servers (die alten Optionen stammen noch <a href=\"https:\/\/www.dirk-hagedorn.de\/?p=2034\">aus dem \u00e4lteren Tipp<\/a>):<\/p>\n<pre>$ sudo vi \/etc\/ssh\/ssh_config.d\/vmsco.conf\r\n\r\nHost vmsco\r\n  <strong>HostKeyAlgorithms +ssh-dss<\/strong>\r\n  KexAlgorithms +diffie-hellman-group1-sha1\r\n  Ciphers +aes128-cbc\r\n\r\nHost 192.168.47.11\r\n  <strong>HostKeyAlgorithms +ssh-dss<\/strong>\r\n  KexAlgorithms +diffie-hellman-group1-sha1\r\n  Ciphers +aes128-cbc\r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Nach dem Upgrade auf Ubuntu 22.04. scheitert erneut der Zugriff per ssh auf eine VM mit einem Uralt-SCO-Unix, in diesem Falle mit folgender Fehlermeldung: $ ssh vmsco Unable to negotiate with 192.168.47.11 port 22: no matching host key type found. Their offer: ssh-rsa,ssh-dss lost connection Warum auch immer (bestimmt aus Sicherheitsgr\u00fcnden) \u00fcbermittelt ssh den id_dsa.pub <a class=\"more-link\" href=\"https:\/\/www.dirk-hagedorn.de\/?p=2066\">Weiterlesen\u00a0\u2026<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[316,22],"tags":[318,432],"class_list":["post-2066","post","type-post","status-publish","format-standard","hentry","category-kurztipp","category-linux","tag-ssh","tag-ssh_config"],"_links":{"self":[{"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/posts\/2066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2066"}],"version-history":[{"count":4,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/posts\/2066\/revisions"}],"predecessor-version":[{"id":2072,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=\/wp\/v2\/posts\/2066\/revisions\/2072"}],"wp:attachment":[{"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2066"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2066"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dirk-hagedorn.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}