Bug 734 - Misleading error message when host key verification is impossible / SSH_ASKPASS impossible.
Summary: Misleading error message when host key verification is impossible / SSH_ASKPA...
Status: CLOSED DUPLICATE of bug 471
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: ssh (show other bugs)
Version: 3.6.1p2
Hardware: All Linux
: P5 trivial
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-10-08 10:42 AEST by Jim Cheetham
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jim Cheetham 2003-10-08 10:42:46 AEST
When connecting to an unknown machine, ssh presents the host key fingerprint to 
the user, and asks for verification. If the user does not verify the 
fingerprint, ssh outputs "Host key verification failed." and terminates.

If (for some strange reason) /dev/tty is unwriteable, and there is no other 
SSH_ASKPASS on the system, ssh still outputs "Host key verification failed." and 
terminates. However, in this case it might be more accurate or helpful to report 
that there is no method to even ask for verification, e.g. "No method available 
to ask for Host key verification".

(I was trying to debug a new sshd setup on a possibly-unstable server from a 
client machine with a broken /dev/tty and no ssh-askpass - the host key message 
made me think that the sshd was sending invalid data, not that the client 
machine had problems of its own)

This is a very low priority/severity report, because the phrase "Host key 
verification failed." could arguably still be correct in these circumstances. 
You might want to view it as an enhancement, except that I feel you shouldn't 
use a single error message for two different conditions.

I note that under the same circumstances, a connection to a known host that 
would normally use a password method outputs "Permission denied" messages for 
keyboard-interactive, which is not as misleading.
Comment 1 Darren Tucker 2003-10-08 12:30:00 AEST
All good points, and there's already a bug open for this.

*** This bug has been marked as a duplicate of 471 ***
Comment 2 Damien Miller 2004-04-14 12:24:19 AEST
Mass change of RESOLVED bugs to CLOSED